HELP FILE

Microsoft Authenticator

Microsoft Authenticator is a multifactor app for mobile devices that generates time-based codes used during the Two-Step Verification process. Please note that one-tap push notification and 6-digit SMS code authentication options are not supported when using this mobile authenticator.

Note: Feature availability may vary depending on your account type.

For LastPass admins, it is recommended that you complete the steps for enabling Multifactor Authentication in the Admin Console.

For LastPass users, you can begin by installing Microsoft Authenticator on your iOS or Android device. Once installed, it is required that you follow all steps in Enable Multifactor Authentication (Users) before proceeding.

Please note that if you have more than 1 Multifactor Authentication option enabled for your account, you must select your desired default authentication option from the drop-down menu at the bottom of your Multifactor Options window in order to be prompted to authenticate with your preferred option when logging in to LastPass.

Topics in this article:

Set up the Microsoft Authenticator app

Set up and configure your account

Use the Microsoft Authenticator

Disable authentication for a new or lost device

About Migrating from Google Authenticator to Microsoft Authenticator

Set up the Microsoft Authenticator app

  1. Download the Microsoft Authenticator app for iOS or Android, then open it.
  2. In the Microsoft Authenticator window, click View your barcode in the "To get started" section at the top of the window.
  3. When prompted, enter your Master Password then click Continue.
  4. On your mobile device, open the Microsoft Authenticator app, tap the Add icon or Add an Account option, then tap Scan barcode.
  5. Use your device camera to scan the barcode, which will automatically populate a new entry for LastPass in the Microsoft Authenticator app.
  6. Back on your web browser in the Microsoft Authenticator window, click OK once the barcode has been scanned.

Set up and configure your account

  1. Enable Multifactor Authentication in your LastPass account.
  2. Click the Edit icon for Microsoft Authenticator.
  3. For the "Enabled" option use the drop-down menu to select Yes.
  4. For the "Permit Offline Access" option, use the drop-down menu to choose from the following:
    • Select Allow if you wish to allow access to Microsoft Authenticator even when you are offline. This will store an encrypted Vault locally so you can log in without using Multifactor Authentication in case of a connectivity issue.
    • Select Disallow to prevent offline access, which requires the use of Multifactor Authentication and to be connected to the internet when using Microsoft Authenticator.
    • Note: If this option is selected and you are not connected to the internet and/or https://lastpass.com is not available, you will be unable to access your Vault. Learn more about offline access.

  5. For the "Barcode" option, click View anytime you need to scan your barcode again.
  6. For the "Private Key" option, click View if your mobile device does not have a camera and you'd like to enter the private key manually into the Microsoft Authenticator app.
  7. For the "Regenerate Key" option, click Regenerate if you lost your mobile device or are concerned that the security of your existing key might have been compromised.
  8. For the "More Information" section, you can choose to be directed to the mobile app download or this article.
  9. Click Update when finished, then enter your Master Password and click Continue.
  10. When prompted, enter the verification code displayed in the Microsoft Authenticator app on your mobile device, then click OK.
  11. Click OK on the confirmation message that Microsoft Authenticator has been successfully set up.

Use the Microsoft Authenticator

  1. Open the Microsoft Authenticator app on your mobile device.
  2. On your desktop web browser, log in to LastPass.
  3. On your web browser, you can verify your login by entering the 6-digit code displayed in the mobile app. If desired, check the box to enable the option, "Trust this computer for 30 days" and provide a computer name, then click Authenticate. Learn more about managing your trusted devices.

Disable authentication for a new or lost device

If your phone number has changed or mobile device used for authentication is lost, you can click I've lost my Microsoft Authenticator device on the Multifactor Authentication window. Once redirected, you can enter your LastPass email address and click Send Email to be sent an email with a set of instructions on how to disable Multifactor Authentication. If you do not receive an email, you may have a secondary security email enabled where the email was sent instead, and/or check your spam/junk email filters. If you are an Enterprise user, your account may have policies enforced that prevent disabling Multifactor Authentication via email. For these users, please contact your LastPass admin to disable it for you.

About Migrating from Google Authenticator to Microsoft Authenticator

Please see the steps outlined in the following resources based on your role within your LastPass account: