Overview

The LastPass integration reviews who has access to your password vault — the LastPass Enterprise user roster, their roles, MFA enrollment, and offboarding status. LowerPlane uses read-only access via the LastPass Enterprise Provisioning API and does not modify anything in LastPass.
LastPass’s usernames are email addresses, so LowerPlane can match each account to a person in your directory for offboarding — and the API exposes per-user MFA, so the MFA check works too.

Prerequisites

You need a LastPass Business/Enterprise plan, admin access to the LastPass Admin Console, and the Enterprise API enabled.

How to Get Your Credentials

1

Log in to the Admin Console

Sign in to the LastPass Admin Console as an admin.
2

Copy your account number (CID)

Your CID is the account number shown in the Admin Console (Dashboard / Security Dashboard).
3

Create a provisioning hash

Go to Advanced → Enterprise API and click Create provisioning hash (or Reset provisioning hash). Copy the generated hash.
4

Save the hash securely

LastPass shows the provisioning hash only once, and resetting it invalidates any prior hash.

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane.
  2. Find LastPass under Security.
  3. Enter your Account Number (CID) and Provisioning Hash.
  4. Click Connect.

What LowerPlane Checks

MFA enabled

Flags any LastPass user who has not enrolled a multi-factor authentication method.

Offboarded access removed

Flags LastPass access still active for an employee who has been offboarded in your HR directory.

User identified

Confirms each account resolves to a named person, not an anonymous or shared account.

Access valid

Verifies each account maps to a current employee in your HR directory whose access has been reviewed.