HELP FILE

Use Duo Security Authentication

Duo Security is a secure, Multifactor Authentication application that can be used as an added layer of security in your LastPass account.

Note: Feature availability may vary depending on your account type.

To get started, LastPass admins must complete the steps for enabling Multifactor Authentication in the Admin Console.

Set up and configure

For users, in order to use Duo Security, a Duo account is required. Register for an account at https://www.duosecurity.com/lastpass.

  1. Install the Duo Mobile app on your iOS or Android device.
  2. Log in to LastPass and access your Vault by doing either of the following:
    • Go to https://lastpass.com/?ac=1 and log in with your username and Master Password.
    • In your web browser toolbar, click the LastPass icon LastPass then click Open My Vault.
  3. Select Account Settings in the left navigation.
  4. Click on the Multifactor Options tab.
  5. Click the Edit icon Edit option for Duo Security.
  6. Follow the steps in the "Configure Duo Security" section here to finish the setup process.

Using Duo Security Authentication

Once you have enabled and set up Duo Security as your multifactor option, you can test your setup by following the instructions here.

If desired, check the box to enable the option, "Trust this computer for 30 days" and provide a computer name, then click Authenticate. Learn more about managing your trusted devices.

Using multiple Multifactor Authentication options

Please note that if you have more than one Multifactor Authentication option enabled for your account, you must select your desired default authentication option from the drop-down menu at the bottom of your Multifactor Options window in order to be prompted to authenticate with your preferred option when logging in to LastPass.

Select preferred Multifactor Authenticator

Disabling authentication for a new or lost device

If your phone number has changed or mobile device used for authentication is lost, you can click I've lost my device on the Multifactor Authentication window. Once redirected, you can enter your LastPass email address and click Send Email to be sent an email with a set of instructions on how to disable Multifactor Authentication. If you do not receive an email, you may have a secondary security email enabled where the email was sent instead, and/or check your spam/junk email filters. If you are an Enterprise user, your account may have policies enforced that prevent disabling Multifactor Authentication via email. For these users, please contact your LastPass admin to disable it for you.

Disable Multifactor Authentication

Additionally, the Duo admin for your account will need log in to Duo and to go to Duo Admin PanelUsers[your account]Phones and remove your phone number. Once removed, log in to your LastPass account and re-enable Duo Security as your multifactor option. You will be prompted to enroll your device again.