Cybersecurity Awareness Month is here - Read more.
Guidance for admins managing users, policies, SSO, MFA, reporting, deployment.
Learn to use LastPass Business features—vaults, sharing, autofill, mobile access, and MFA.
Resources to help admins manage users, policies, SSO, MFA, deployments.
Resources to monitor SaaS usage, detect risks, enforce policies, and strengthen security.
I’m exploring Advanced MFA and Workstation MFA to strengthen security for our organization. From what I’ve read, Advanced MFA can protect vault logins, SSO apps, VPNs, and even includes contextual policies like geofencing. Workstation MFA adds a second layer of authentication when employees log into Windows or macOS…
No organization is breach‑proof, but resilient organizations recover quickly, minimize downtime, and avoid ransom payments because backups are robust, incident playbooks are practiced, and identity is locked down. Make sure you follow this checklist to ensure your business remains secure: Implement phishing-resistant…
Digital squatting includes typosquatting, combosquatting, TLD abuse, and homograph attacks. These deceptive tactics all aim to capitalize on established brands and differ in their specific techniques. Digital squatting and phishing are often treated as separate threat vectors, but they are deeply intertwined. Digital…
Here are a few simple steps SMBs can take to better protect themselves against these threats: Register obvious variations of your domain (cheap and effective). Enable MFA everywhere (cuts off most credential theft). Use email security tools that check for lookalike domains. Tools like DNS firewalls can automatically block…
Prohibit Sharing Except for Shared Folders LastPass offers password sharing to help employees securely and conveniently share logins with others inside and outside the organization. By default, individuals can share items one-on-one, or teams can easily collaborate and access shared accounts by setting up shared folders.…
Here's the short: Human identities are non-deterministic (behavior changes based on context) and often authorized through RBAC, ABAC, or other identity governance controls. Bot identities are machine accounts that exhibit deterministic behavior. They operate under pre-defined permissions, which means specific inputs result…
While traditional IAM relies on passwords and MFA, AI IAM must navigate: Volumes of ephemeral agents and their token lifecycles Cross-agent communications Cross-app permissions Unlike human users or service accounts, AI agents aren’t tied to roles or even a specific application. Instead, they make decisions, take actions,…
Traditional IAM falls short because pre-defined identity governance controls like RBAC are too broad for autonomous AI agents, whose behavior can be manipulated in real-time. In the 2025 CoPhish attack, threat actors created fake AI chatbots on Microsoft’s trusted Copilot Studio site and then sent phishing links…
OAuth 2.0 access tokens expire quickly but refresh tokens are functionally long-lived. That’s why the CoPhish attack was so dangerous. The AI agent didn’t just get temporary access; it got persistent access through refresh tokens that let it create access tokens at will. And although OAuth 2.1 isn’t finalized, it tries…
#1 AI agents don’t have their own identity This was one of the most debated issues. Attendees asked, “Should agents be treated as a service principal, workload identity, or new entity?” Some organizations are treating agents like human users, complete with licenses and permissions. Meanwhile, others are using hybrid models…