Password Manager for the Office of Information Technology
Lastpass: Secure Password Manager
Overview
The Office of Information Technology (OIT) offers a secure password manager, LastPass, to its employees. LastPass stores all of your usernames and passwords in one safe place called a vault. After you save a password to your vault, LastPass always remembers it for you. When you need to log in to a website, LastPass enters your username and password for you! LastPass accounts are available to OIT employees.
LastPass is intended for University use only. It is not intended for storing personal credentials.
Getting Started
- Request. OIT employees can request an account by filling out the LastPass request form
- Download the LastPass browser extension on all browsers you use to log in to LastPass. This is required to help recover your master password if needed.
- Set-Up. When the request has been approved, you will receive an email with instructions to set up your account.
- Follow the step-by-step instructions in Duo MFA for LastPass to set up the LastPass extension in all the browsers you downloaded it to. Not doing so could result in Duo for LastPass not being properly set up.
Best Practices
Browser Extension
- Download and install the LastPass browser extension on at least 2 different browsers. It will help in recovering your master password when needed.
- Log in to LastPass at least once using each of the browser extensions installed. For best results, always log in using the extension.
Set Up Password Recovery Options
Along with installing and logging in to more than one browser extension, adding more password recovery options will provide more options to recover your password when needed.
- Follow instructions to Setup SMS (text) recovery options for Android and iOS devices.
- Set a master password reminder or hint.
Shared Folder
- Create a Shared Folder.
- Edit users and access for a Shared Folder.
Note: Always grant at least one other user as an admin to your shared folders. This additional administrator is needed if your account becomes disabled, etc. LastPass administrators cannot see or transfer the contents of your shared folders to another user, nor do they have the authority to do so. If you change a password stored in a folder, log out and back in to LastPass to propagate the change to all the other users.