How do I convert an existing LastPass user to a federated (AD FS or PingFederate) user?

As a best practice, it is recommended that you inform your non-federated users when their account will be converted to a federated status, as those users who are actively logged in to LastPass while their account is being migrated will be logged out once the migration process is complete. Once logged out, all newly federated users will be required to use their Active Directory credentials in order to log in to LastPass from now on. Additionally, an email notification is automatically sent to newly federated users that contains instructions for their new login experience going forward.
- Converting existing users to a federated user status is only supported if the users are listed in the provisioning groups within the user group filter of the Sync settings for the LastPass AD Connector (instructions here) and were synced to LastPass via the LastPass AD Connector.
- Users that were created manually or by another method are unable to be converted to federated users using the steps outlined below. For those existing users created by another method, make sure the users are part of the groups that are synced to LastPass via LastPass AD Connector.
- Once the migration process has been started on the LastPass AD Connector, all active syncing will be paused, and will resume again after the migration process is complete.
- If an existing (non-federated) LastPass Business user account has linked a personal account before they are migrated, the personal account will become unlinked during the migration process.
- All federated users must always log in using a LastPass component (i.e., web browser extension, desktop app, or mobile app) in order to be redirected to your organization's Identity Provider (AD FS or PingFederate) sign in page. This means that logging in via your online web vault (via the LastPass website) at https://lastpass.com/?ac=1 does not support federated login.
Step #1: Set up federated login for LastPass Business using AD FS or PingFederate
Step #2: Select the users you want to convert in the Admin Console
Step #3: Migrate your selected users in the LastPass AD Connector
Step #4: Check federated user statuses in Admin Console
Once the LastPass AD Connector displays that the migration is complete, return to the Admin Console to oversee the progress of your federated user migration.
- To see your end user's experience, please see Federated Login Experience for LastPass Users.
- For additional help with troubleshooting, please see Troubleshooting Federated Login for Active Directory Federation Services (AD FS).