LastPass configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On LastPass, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the LastPass connector needs.
Checks (11)
severity: high Weak Master Password fix difficulty: medium #
Enforce a minimum master password strength policy to eliminate weak master passwords
- Navigate to LastPass Admin > Policies
- Enable the minimum master password strength policy
- Set the minimum strength score to 50 or higher
- Notify affected users to update their master password
- Follow up to verify compliance after the grace period
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: critical Very Weak Master Password fix difficulty: medium #
Enforce a minimum master password strength of 50 or higher in LastPass policies
- Navigate to LastPass Admin > Policies
- Enable minimum master password strength policy
- Set minimum strength to 50 or higher
- Require affected user to change password immediately
- Verify compliance after grace period
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Empty Vault User fix difficulty: easy #
Send onboarding reminders to LastPass users with empty vaults and remove unused licenses
- Navigate to LastPass Admin > Users
- Find user with no saved sites
- Send onboarding reminder
- Provide training resources for password migration
- Remove license if user is not adopting
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Stale Master Password fix difficulty: easy #
Notify LastPass users with stale master passwords to rotate them and enforce a password age policy
- Navigate to LastPass Admin > Users
- Find the user
- Send password rotation reminder via LastPass policy
- Follow up if not changed within grace period
- Consider enforcing password age policy
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Master Password Never Changed fix difficulty: easy #
Notify LastPass users who have never changed their master password to rotate it
- Navigate to LastPass Admin > Users
- Find the user
- Send password change notification
- Enable policy requiring initial password change
- Follow up to verify completion
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: critical Admin Stale Master Password fix difficulty: easy #
Enforce immediate master password rotation for LastPass admin accounts with stale passwords
- Navigate to LastPass Admin > Users
- Find the admin user
- Enforce immediate password rotation
- Verify new password meets strength requirements
- Enable password age policy for admin accounts
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Low Shared Folder Security Score fix difficulty: medium #
Improve the security score of LastPass shared folders by updating weak or reused passwords
- Navigate to LastPass Admin > Shared Folders
- Open the affected folder and review the security score details
- Identify individual entries with weak or reused passwords
- Require owners to update those passwords to strong, unique values
- Re-check the folder security score after updates are complete
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Critically Low Shared Folder Score fix difficulty: medium #
Update weak or reused passwords in LastPass shared folders to improve the security score
- Navigate to LastPass Admin > Shared Folders
- Review the security score details
- Identify weak or reused passwords within the folder
- Require password updates for low-scoring entries
- Re-check score after remediation
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: critical Admin With Weak Master Password fix difficulty: medium #
Require the admin to immediately update their master password to meet the higher strength threshold
- Navigate to LastPass Admin > Users
- Locate the admin with a weak master password
- Notify the admin to change their master password immediately
- Enforce a minimum master password strength of 75 or higher for admin accounts
- Verify the password strength after the change
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Empty Shared Folder fix difficulty: easy #
Delete orphaned shared folders that have no members
- Navigate to LastPass Admin > Shared Folders
- Locate the shared folder with zero members
- Confirm that no one needs access to the folder contents
- Delete the empty shared folder
- Review folder creation processes to prevent orphaned folders
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: critical Admin Master Password Never Changed fix difficulty: easy #
Require the admin to immediately change their master password from the initial value
- Navigate to LastPass Admin > Users
- Locate the admin who has never changed their master password
- Notify the admin to change their master password immediately
- Enable the policy requiring initial password change after account creation
- Verify the password was changed and meets strength requirements
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10