Skip to content

LastPass access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On LastPass, Black Cat runs 13 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the LastPass connector needs.

Checks (13)

severity: medium Dormant Account fix difficulty: easy #

Disable or remove LastPass user accounts that have been dormant for 90 or more days

  1. Navigate to LastPass Admin > Users
  2. Filter by last login date to identify dormant accounts
  3. Confirm with the user's manager whether access is still required
  4. Disable or delete the account if no longer needed
  5. Review dormant account policies and set automatic deprovisioning rules

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Admin Dormant fix difficulty: medium #

Demote or disable dormant LastPass admin accounts after verifying with management

  1. Navigate to LastPass Admin > Users
  2. Find the dormant admin
  3. Verify with management if admin access is still needed
  4. Demote to regular user or disable account
  5. Transfer admin responsibilities if needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Never Logged In Account fix difficulty: easy #

Remove or revoke LastPass user accounts that have never been used since provisioning

  1. Navigate to LastPass Admin > Users
  2. Filter by last login to identify accounts with no login history
  3. Verify with the account owner or manager whether the account is still needed
  4. Delete or deactivate accounts that are no longer required
  5. Audit the provisioning workflow to prevent unused account accumulation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Admin Never Logged In fix difficulty: easy #

Remove or revoke admin privileges from LastPass admin accounts that have never logged in

  1. Navigate to LastPass Admin > Users
  2. Find the unused admin account
  3. Verify if account was created intentionally
  4. Remove admin privileges or delete account
  5. Audit admin creation process to prevent recurrence

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Disabled Account Not Removed fix difficulty: easy #

Permanently delete LastPass user accounts that have been disabled but not yet removed

  1. Navigate to LastPass Admin > Users
  2. Filter by status to find all disabled accounts
  3. Confirm that no data recovery is required before deletion
  4. Permanently delete each disabled account
  5. Establish a policy to remove disabled accounts within a defined retention window

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Shared Folder Admins fix difficulty: easy #

Reduce the number of admins in LastPass shared folders to the minimum required

  1. Navigate to LastPass Admin > Shared Folders
  2. Open the affected folder and review the member list
  3. Identify admin members who do not require full admin rights
  4. Downgrade excess admins to read-only or standard access
  5. Document the approved admin list for future reviews

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Shared Folder All Admin fix difficulty: easy #

Downgrade at least some members of LastPass shared folders where all users have admin rights

  1. Navigate to LastPass Admin > Shared Folders
  2. Open the affected folder and review the member list
  3. Identify members who only need read or standard access
  4. Downgrade those members to a non-admin role
  5. Retain admin rights only for users who manage the folder

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Shared Folder No Read-Only Users fix difficulty: easy #

Add read-only members to LastPass shared folders that currently grant every user write access

  1. Navigate to LastPass Admin > Shared Folders
  2. Open the affected folder and review member permissions
  3. Identify members who only need to view credentials, not modify them
  4. Change those members' permissions to read-only
  5. Apply least-privilege access across all shared folders

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Shared Folder Single Admin fix difficulty: easy #

Add a second admin to LastPass shared folders that have only a single admin

  1. Navigate to LastPass Admin > Shared Folders
  2. Find the affected folder
  3. Add at least one additional admin user
  4. Ensure backup admin has appropriate access level
  5. Document shared folder ownership

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Shared Folder Excessive Users fix difficulty: medium #

Reduce LastPass shared folder membership by removing unnecessary users or splitting the folder

  1. Navigate to LastPass Admin > Shared Folders
  2. Review membership list for the large folder
  3. Identify users who no longer need access
  4. Consider splitting into smaller role-based folders
  5. Remove unnecessary members

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low User Not Assigned to Any Group fix difficulty: easy #

Assign the user to at least one LastPass group to ensure group-level policies apply

  1. Navigate to LastPass Admin > Groups
  2. Identify the appropriate group for the user based on their role
  3. Add the user to the group
  4. Verify that group-level policies now apply to the user

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Disabled Account With Admin Privileges fix difficulty: easy #

Revoke admin privileges from the disabled LastPass account before or during deactivation

  1. Navigate to LastPass Admin > Users
  2. Locate the disabled admin account
  3. Remove admin privileges from the account
  4. If the account is no longer needed, permanently delete it
  5. Review the offboarding process to ensure admin demotion happens before disabling

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Recently Created Admin Account fix difficulty: easy #

Verify that the recently created admin account was authorized through the proper access management process

  1. Navigate to LastPass Admin > Users
  2. Locate the admin account created within the last 7 days
  3. Verify the promotion was requested through your access management process
  4. Confirm the account belongs to an active employee or contractor
  5. If unauthorized, immediately revoke admin privileges
  6. File an incident report if privilege escalation is suspected

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More LastPass checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial