A LastPass vault holds every other password you have, so the master password is the one that must never be enough on its own. With multifactor authentication on, LastPass also asks for the code from your authenticator when you log in — LastPass notes that this keeps the account closed even if the master password is obtained, for example by a keylogger.
Turn on multifactor authentication in LastPass
Choose the “Google Authenticator” option: it produces standard time-based codes, which any authenticator app can generate. LastPass Authenticator is LastPass’s own phone app and is set up with that app alone. Google Authenticator and Microsoft Authenticator cannot be on at the same time. LastPass Free includes authenticator apps; on Teams and Business, your admin’s policies may limit these settings.
- Log in at lastpass.com on your computer with your email address and master password, and open your vault.
- Select “Account settings” in the left navigation menu, then the “Multifactor Options” tab.
- Select the Edit icon for “Google Authenticator”, set “Enabled” to “Yes”, and choose whether to “Permit Offline Access”.
- Next to “Barcode”, click “View” and enter your master password if asked. “View” next to “Private Key” shows the key for manual entry instead.
- LastPass shows a QR code. Leave it on the screen and add it to the extension as described below — then select “Update”, enter your master password, and type the code from the extension when LastPass asks for it.
Add LastPass to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the LastPass page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to LastPass and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- LastPass confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on LastPass’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeKnow your way back into LastPass
LastPass’s help does not describe backup codes for this option. Instead, if you lose the authenticator but know your master password, choose “Additional Multifactor Options” at the code prompt and select the “I’ve lost my … device” link: LastPass emails you a link that turns multifactor authentication off. That makes the email account behind LastPass your way back — protect it with its own two-step verification. LastPass also recommends turning on more than one multifactor option, ideally on different devices.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Which authenticator option should I pick in LastPass?
- “Google Authenticator”. It is not tied to Google’s app: it uses standard codes that any authenticator produces, including the Authenticator extension in Chrome. “Microsoft Authenticator” works the same way, but LastPass allows only one of the two at a time. It is available on LastPass Free as well — only hardware keys need Premium.
- Can I keep the code for LastPass inside LastPass?
- Not the one that opens LastPass — you would need the vault to unlock the vault. LastPass can also hold codes for other sites, but then one master password guards both your passwords and their second step. A separate authenticator, like this extension, keeps the two apart; lock it with its own password too.
- What if I lose access to my authenticator?
- If you know your master password, use the “I’ve lost my … device” link under “Additional Multifactor Options” at the code prompt — LastPass emails you a link that turns multifactor authentication off. Then turn it on again with a new QR code, and if the device was lost or stolen, change your master password as LastPass advises.
- Why does LastPass say my code is wrong?
- Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, regenerate the key: edit “Google Authenticator” in Multifactor Options, click “Regenerate” next to “Regenerate Key”, and add the new QR code to the extension in place of the old account.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free