cancel
Showing results for 
Search instead for 
Did you mean: 
GlennD
GoTo Manager

Passwordless is possible - today!

What is Passwordless? 

Passwordless login is a new way to access your LastPass Vault without having to enter your master password. Once set up, you will simply authenticate, rather than having to type a password to access your vault.  Here’s how to set it up. 

 

So, do I need my master password? 

Yes, for now. There are three scenarios where you'll need your master password: 1) to set up passwordless login, 2) in case of a failed authentication attempt, or 3) to make security changes to your account. Eventually, LastPass will remove the master password altogether, but that takes time. This is just the first step in LastPass' passwordless journey. 

 

Is the Authenticator app the only way to use Passwordless? 

The LastPass Authenticator app is the first authentication method to be released. Over the next few months, LastPass will be introducing additional methods to log into your vault including biometrics and security keys like Yubikey. 

 

Glenn is a member of the GoTo Community Care Team.

Was your question answered? Please mark it as an Accepted Solution.
Was a post helpful or informative? Give it a Kudo!
57 REPLIES 57
belmopan
New Contributor

I was using LastPass Authenticator for a while. Then it stopped working and I couldn't figure out how to obtain a barcode to reconnect. Then, recently, LastPass displayed a barcode: but when I scanned it I simply got an error message.

 

Please don't push this authenticator until you've got it working.

AshC
GoTo Moderator

Hi all, thanks for your early feedback.  We're always interested to hear what customers are experiencing. 

 

I wanted to address some concerns regarding the LastPass Authenticator and Passwordless functionality: 

  1. While it is currently the only compatible app to use with Passwordless Login, we will be adding more MFA options in the future. 
  2. Only the LastPass Authenticator can be activated as your 2FA, but you can still set up all available recovery options for the account should any problems occur. 
  3. If you are experiencing failure with the LastPass Authenticator app, you can reach out to Customer Support as a paid subscriber, or create a new thread in the Community if you don't find the error already referenced in a previous post or on the support site itself
  4. Passwordless Login does not take the place of your actual password, and LastPass will always require this when you log in from a new device or location. 
  5. If you have lost or cannot access the mobile device set up with LP Authenticator, there is a solution available that requires access to your LastPass email address.  In a worst case scenario, we can always help you disable 2FA after confirming your identity through a series of security questions.  Your LastPass password will be required to log back in and set up 2-factor authentication again. 

 


Ash is a member of the GoTo Community Care Team.

Was your question answered? Please mark it as an Accepted Solution.
Was a post helpful or informative? Give it a Kudo!
nope123
New Contributor

I enabled it and discovered 2 things:

 

1) push notifications do not show up to my android phone - the lastpass authenticator app never wakes up on its own, I never see anything.  If I go into the authenticator app and then enter the number, I can log in.  But this totally defeats the purpose of convenience!

 

2) when I enable passwordless login, I no longer have the option to enter my password, apparently I HAVE to use the authenticator app.  I don't want that -- is there a way to use the authenticator app, but if your phone is not around enter the password?

 

Any help is appreciated. I'd like to use this cool new feature, but as it is it doesn't work.

AshC
GoTo Moderator

@nope123  If your phone is not accessible, you can still use passwordless login to log in to SSO apps and/or workstations by pairing another device with the LastPass Authenticator or contacting your LastPass admin. 

 


Ash is a member of the GoTo Community Care Team.

Was your question answered? Please mark it as an Accepted Solution.
Was a post helpful or informative? Give it a Kudo!
BoJackHorseman
New Contributor

I enabled the passwordless login today and it seems to work well.

 

Can this be used for master password reprompts too? I hate typing passwords and want to simply tap approve or use my Mac fingerprint reader for that.

 

Also looking forward to optionality. Would like to be able to use a YubiKey and fingerprint as well to log in. I really only want to type in the master password when all other options are unavailable to me.

skrippi
New Contributor

Is there any way to use biometrics like my fingerprint to insert my login data for a specific website instead of entering my whole Master Passwort every time? I am talking about the Firefox Extension.

jpenny84
Respected Contributor

Is there a technical writeup that explains how this feature works? I'm just trying to understand on a high level how encryption is maintained in an offline environment since LastPass Authenticatior is the only thing needed for subsequent logins on that machine.

AshC
GoTo Moderator

@BoJackHorseman  Passwordless login does not completely remove the need for your actual password, and additional 2-factor authentication methods will be available in the future. 

 

@jpenny84  Re-encryption only occurs when the Authenticator confirms your identity, which is automatically required when LastPass is not in use for 24 hours. 

 


Ash is a member of the GoTo Community Care Team.

Was your question answered? Please mark it as an Accepted Solution.
Was a post helpful or informative? Give it a Kudo!
Glimmie
Active Contributor

I have extension version 4.97.0.2 on Firefox and I don't see the Passwordless Options tab.

So a no go for me. Must say i'm on a trail (lastpass business)

 

But when i send a invite for setup passwordless authentication I recieve a mail.

LP Authenticator installed and working. In the recieved mail clicking the button Activate Lastpass MFA

It opens a site and I see a button to link my phone. Clicking button. LP Authenticator app opens and then nothing.

 

My user status of passwordless auth still on invited.

BoJackHorseman
New Contributor

Why though? Passwordless authenticates someone for Last Pass. Why can't / won't it reauthenticate for master password reprompts?