Manage multifactor authentication options for users in the new Admin Console
Restrict the multifactor authentication options available for use by users within your LastPass Business account.
For additional security measures, you can also choose to enforce various policies for your users to adhere to when using multifactor authentication when accessing their LastPass vaults.
By default, all multifactor authentication options are enabled for LastPass Business accounts.
You can manage your desired authentication options by doing the following:
- Log in with your email address and master password to access the new Admin Console at https://admin.lastpass.com.
- If prompted, complete steps for multifactor authentication (if it is enabled for your account).
- Go to .
- Uncheck the box(es) to disable your desired multifactor authentication option(s), and leave the box(es) checked for the options you want enabled.
- Choose from the following options:
- Click Update when finished.
Disable multifactor authentication
You can disable multifactor authentication account-wide by disabling all multifactor options, disabling multifactor for users with it already enabled, and deleting all multifactor authentication policies.
-
- Log in with your email address and master password to access the new Admin Console at https://admin.lastpass.com.
- If prompted, complete steps for multifactor authentication (if it is enabled for your account).
- Go to .
- Uncheck all boxes next to all multifactor authentication options.
- Click Update.
- In the top toolbar, select the Users tab and check the boxes next to the users that have Enabled Multifactor.
- Click Disable multifactor.
- If policies are enforced to require use of any multifactor authentication option, you must delete those policies.
Disable all multifactor authentication options (that are already enabled).
Disable multifactor authentication for users (that already have it enabled).
Disable all multifactor authentication policies.
About multifactor authentication for Active Directory Federation Services (AD FS)
Multifactor authentication set up within LastPass is not supported for federated users.
White it is strongly recommended that you protect your account with multifactor authentication, it must be set up at the Identity Service Provider level (AD FS) – meaning this authentication must be disabled within the new Admin Console and end user Account Settings – as it will result in federated users being unable to access their vault.