Skip to content

LastPass configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On LastPass, Black Cat runs 11 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the LastPass connector needs.

Checks (11)

severity: high Weak Master Password fix difficulty: medium #

Enforce a minimum master password strength policy to eliminate weak master passwords

  1. Navigate to LastPass Admin > Policies
  2. Enable the minimum master password strength policy
  3. Set the minimum strength score to 50 or higher
  4. Notify affected users to update their master password
  5. Follow up to verify compliance after the grace period

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical Very Weak Master Password fix difficulty: medium #

Enforce a minimum master password strength of 50 or higher in LastPass policies

  1. Navigate to LastPass Admin > Policies
  2. Enable minimum master password strength policy
  3. Set minimum strength to 50 or higher
  4. Require affected user to change password immediately
  5. Verify compliance after grace period

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Empty Vault User fix difficulty: easy #

Send onboarding reminders to LastPass users with empty vaults and remove unused licenses

  1. Navigate to LastPass Admin > Users
  2. Find user with no saved sites
  3. Send onboarding reminder
  4. Provide training resources for password migration
  5. Remove license if user is not adopting

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Stale Master Password fix difficulty: easy #

Notify LastPass users with stale master passwords to rotate them and enforce a password age policy

  1. Navigate to LastPass Admin > Users
  2. Find the user
  3. Send password rotation reminder via LastPass policy
  4. Follow up if not changed within grace period
  5. Consider enforcing password age policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Master Password Never Changed fix difficulty: easy #

Notify LastPass users who have never changed their master password to rotate it

  1. Navigate to LastPass Admin > Users
  2. Find the user
  3. Send password change notification
  4. Enable policy requiring initial password change
  5. Follow up to verify completion

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical Admin Stale Master Password fix difficulty: easy #

Enforce immediate master password rotation for LastPass admin accounts with stale passwords

  1. Navigate to LastPass Admin > Users
  2. Find the admin user
  3. Enforce immediate password rotation
  4. Verify new password meets strength requirements
  5. Enable password age policy for admin accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Low Shared Folder Security Score fix difficulty: medium #

Improve the security score of LastPass shared folders by updating weak or reused passwords

  1. Navigate to LastPass Admin > Shared Folders
  2. Open the affected folder and review the security score details
  3. Identify individual entries with weak or reused passwords
  4. Require owners to update those passwords to strong, unique values
  5. Re-check the folder security score after updates are complete

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Critically Low Shared Folder Score fix difficulty: medium #

Update weak or reused passwords in LastPass shared folders to improve the security score

  1. Navigate to LastPass Admin > Shared Folders
  2. Review the security score details
  3. Identify weak or reused passwords within the folder
  4. Require password updates for low-scoring entries
  5. Re-check score after remediation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical Admin With Weak Master Password fix difficulty: medium #

Require the admin to immediately update their master password to meet the higher strength threshold

  1. Navigate to LastPass Admin > Users
  2. Locate the admin with a weak master password
  3. Notify the admin to change their master password immediately
  4. Enforce a minimum master password strength of 75 or higher for admin accounts
  5. Verify the password strength after the change

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Empty Shared Folder fix difficulty: easy #

Delete orphaned shared folders that have no members

  1. Navigate to LastPass Admin > Shared Folders
  2. Locate the shared folder with zero members
  3. Confirm that no one needs access to the folder contents
  4. Delete the empty shared folder
  5. Review folder creation processes to prevent orphaned folders

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical Admin Master Password Never Changed fix difficulty: easy #

Require the admin to immediately change their master password from the initial value

  1. Navigate to LastPass Admin > Users
  2. Locate the admin who has never changed their master password
  3. Notify the admin to change their master password immediately
  4. Enable the policy requiring initial password change after account creation
  5. Verify the password was changed and meets strength requirements

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More LastPass checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial