Enterprise Admin: Global Password Iteration Control

cancel
Showing results for 
Search instead for 
Did you mean: 

Enterprise Admin: Global Password Iteration Control

0 Kudos

Enterprise Admin: Global Password Iteration Control

As an Enterprise admin, given the recent security concerns and available recommendations, the ability to globally set the password iteration number across the enterprise to force a higher level of security around that setting would be a great addition to help ease the minds of those still concerned about the recent breaches.

 

"In 2021, OWASP recommended to use 310,000 iterations for PBKDF2-HMAC-SHA256 and 120,000 for PBKDF2-HMAC-SHA512."

As LastPass uses SHA256, my expectation would be able to increase the number to 310,000 for all enterprise users.