Overview
The LastPass integration reviews who has access to your password vault — the LastPass Enterprise user roster, their roles, MFA enrollment, and offboarding status. LowerPlane uses read-only access via the LastPass Enterprise Provisioning API and does not modify anything in LastPass.LastPass’s usernames are email addresses, so LowerPlane can match each account to a person in your directory for offboarding — and the API exposes per-user MFA, so the MFA check works too.
Prerequisites
How to Get Your Credentials
Log in to the Admin Console
Sign in to the LastPass Admin Console as an admin.
Copy your account number (CID)
Your CID is the account number shown in the Admin Console (Dashboard / Security Dashboard).
Create a provisioning hash
Go to Advanced → Enterprise API and click Create provisioning hash (or Reset provisioning hash). Copy the generated hash.
Connecting in LowerPlane
- Go to Settings > Integrations in LowerPlane.
- Find LastPass under Security.
- Enter your Account Number (CID) and Provisioning Hash.
- Click Connect.
What LowerPlane Checks
MFA enabled
Flags any LastPass user who has not enrolled a multi-factor authentication method.
Offboarded access removed
Flags LastPass access still active for an employee who has been offboarded in your HR directory.
User identified
Confirms each account resolves to a named person, not an anonymous or shared account.
Access valid
Verifies each account maps to a current employee in your HR directory whose access has been reviewed.