Basic
LIMITATION
LP BUSINESS
Federated Login
Business Policies
100

This identity system allows users to sign in to LastPass using their corporate credentials rather than a separate master password.

Federated Login

100

LastPass federated users cannot use this type of authentication method inside LastPass itself; it must be enforced at the IdP level instead. (TRUE Or FALSE)

TRUE

100

LastPass uses this encryption model where data is only decrypted on the user’s device and never visible to LastPass itself.

Zero-Knowledge Architecture

100

During login, federated users must have this enabled in their browser or they will be unable to complete authentication.

the LastPass browser extension

100

This is the approximate number of configurable policies available to admins in LastPass Business, enabling granular control over user security settings.

 100+ policies

200

This term describes the process where a user signs into multiple apps—including LastPass—after authenticating once.

SSO

200

Because the browser extension must stay online to retrieve a user’s encryption key, this type of login is not available for federated users.

offline access

200

This LastPass Business dashboard provides visibility into weak, reused, and compromised passwords across the entire organization.

Security Dashboard 

200

Super admins AND users who were not synced from the directory (that is, users added manually in the Admin Console) are not eligible for federation.

Not eligible for federation

200

This LastPass policy ensures that when new user accounts are created server‑side, their encrypted sharing key is generated automatically—allowing them to receive shared folders without needing to log in first.

Pre‑create Sharing Key

300

What policy should be enabled before we begin the Federated login setp?

Permit Super Admin to Reset MasterPassword

300

This LastPass feature cannot be used by federated users because their master password comes directly from the IdP, not LastPass.

 One‑Time Password (OTP) 

300

This centralized tool allows IT to monitor password health, enforce policies, manage users, and control security settings organization‑wide.

Unified Admin Console

300

An existing user that is not federated and has not been selected for federation.

Not Federated

300

This policy sends an email alert to specified recipients whenever a user account becomes temporarily locked due to repeated failed login attempts.

 Notify Admins Upon User Lockout

400

It refers to linking a company's existing "user directory" with other applications and services, making user management easier and more secure.

Directory integration

400

If a super admin uses the “Permit super admins to reset master passwords” policy to recover a federated user’s account, the user is converted into this account type.

non‑federated user

400

LastPass Business automatically provides each employee with a free family account, improving security beyond the workplace.

Families as a Benefit

400

It is a feature in Microsoft Entra ID (formerly Azure AD) that allows an admin to manually provision a user or group immediately to an integrated application — including LastPass when using SCIM provisioning

Provision on demand

400

A LastPass admin must have this policy enabled in order to access and manage shared folders, including adding users and viewing shared folder details.

 Permit Super Admins to Access Shared Folders

500

It is an automated addition of users to a software, in this case, LastPass

User Provisioning

500

Federated users are unable to activate this security layer within LastPass, since it must be managed exclusively through their Identity Provider to avoid login failures.

multifactor authentication

500

This permission level allows a user to modify items inside a shared folder and invite others but does not make them a LastPass admin.

the “Administrator” shared folder permission

500

What happens if an admin deletes a user in EntraID?

The users are disabled in the LastPass admin console

500

Enabling this policy ensures that the same multifactor requirements for a company’s main account are applied to employees’ linked personal LastPass accounts

Apply parent account MFA policy

M
e
n
u