LastPass admins can set up IP policies to define which IP address ranges from which users are allowed or denied access when using the LastPass Authenticator app for authentication.
- Log in and access the Admin Console at https://lastpass.com/company/#!/dashboard.
- Select MFA or SSO & MFA in the left navigation.
- To manage access policies based on IP addresses, go to in the left navigation.
- To create an allowed IP range:
- Click +Create allowed IP range.
- Enter the IP Addresses and Tag Name and click Add.
Result: A warning window displays.
- To copy your IP, click the Copy icon.
- To activate and assign the IP Policy to users, click Setup policy.
- To skip setting up the policy, click Cancel.
Note: Allowlist IP Policies will remain inactive until they are assigned to users.
- On the Manage Policy page, click +New Policy to continue setting up the policy.
- Enter the Policy Name and select the saved IP Addresses policy you created.
- If needed, assign Geo-fence.
- To limit access to a specific time range, add Policy Time Range.
- Select Permanent Policy or Temporary Policy.
Note: If you choose a Temporary Policy, select a date for the policy.
- To create a denied IP range:
- Click +Create denied IP range.
- Enter the denied IPs and tag name and click Add.
Result: A warning window displays.
- To block access for all users and all applications from the denied IP addresses, click Save IP. To cancel the denied IP, click Cancel.
- Edit the IP Policies.
- Select a policy and edit the policy information.
- To delete the policy, click Delete.
- To activate an inactive Geofencing policy or manage access to a policy, click Access and select a policy.