product icon

How do I enable step-up authentication for SSO apps as a LastPass admin?

    LastPass Business admins can enable the "step-up authentication" feature to allow users to sign in to their assigned SSO apps using stored biometrics (face or fingerprint) via push notification in the LastPass Authenticator app in place of entering their master password.

    Note: This feature requires an account with the LastPass Business + Advanced MFA add-on. How do I upgrade my LastPass Business account with an add-on?
    About this task: To enable step-up authentication for an SSO app, LastPass Business admins can do the following:
    1. Add your desired SSO app in the new Admin Console (instructions here).
    2. During the "Set up LastPass" process (finalizing app configuration, part 3), enable the Step-up authentication setting.
      Remember: Passwordless login for SSO apps only supports authentication using stored biometrics (face or fingerprint) via push notification in the LastPass Authenticator app.
    3. Assign your desired users to finish the app setup.
    Results: You have enabled step-up authentication for your SSO app.
    What to do next: Inform your assigned users they can now sign in to the SSO app using stored biometrics (face or fingerprint) via push notification in the LastPass Authenticator app in place of entering their master password.