Digital Identity

LastPass

Passwordless authentication using YubiKey with layered fallback and recovery methods.

← Back to Digital Identity
🔓 Daily Login
🔐 Authentication

Configured

Primary Authentication
  • Passwordless using YK-03 Nano (FIDO2)
Alternative Authentication
  • LastPass Authenticator
  • Microsoft Authenticator
  • Master Password
Master Credential
  • Master Password changed to a new Diceware-based passphrase.
  • The passphrase meets the LastPass complexity requirements.
  • A printed recovery copy is stored securely offline.
  • The passphrase is also being learned for independent recall.
Confirmed Behaviour
  • LastPass currently supports only one registered FIDO2 security key.
  • Registering a new FIDO2 key replaces the previous registered key.
🛟 Account Recovery

Configured

Authentication methods allow normal login. Recovery methods regain access if authentication or the master password cannot be used.

Recovery Methods
  • Printed Master Password
  • Recovery One-Time Password (OTP)
  • Face ID account recovery
Optional
  • SMS Account Recovery
Configuration
  • Master Password changed successfully.
  • Printed recovery copy created and stored securely offline.
  • Recovery One-Time Password generated and stored securely offline.
Recommendation: SMS Account Recovery is not recommended for normal operation because of SIM swap risk. Only enable it if an additional recovery method is specifically required.
🆘 Emergency Access

Not Configured

Purpose

Emergency Access allows another trusted LastPass user to request access to the vault after a configurable waiting period. The owner is notified immediately and may reject the request before the waiting period expires.

Recommended Use
  • Estate planning.
  • Spouse or executor.
  • Business continuity.
Notes
Emergency Access is separate from authentication and account recovery.
🔑 Hardware
KeyModelLastPass RoleStatus
YK-01YubiKey 5C NFCNot assignedAvailable
YK-02YubiKey 5C NFCNot assignedAvailable
YK-03YubiKey 5C NanoWindows Passwordless KeyRegistered and Tested

YK-03 is dedicated to LastPass. YK-01 and YK-02 remain available for services that support multiple FIDO2 security keys such as Microsoft, GitHub, Google, Proton and Cloudflare.

🛠️ Configuration Guide
Configure Security Key
  1. Connect YK-03.
  2. Open Windows Settings.
  3. Accounts → Sign-in Options.
  4. Security Key → Manage.
  5. Create or change the FIDO2 PIN.
Configure LastPass Authenticator
  1. Install LastPass Authenticator on iPhone.
  2. Open LastPass Account Settings.
  3. Multifactor Options.
  4. Configure LastPass Authenticator.
  5. Pair the iPhone.
  6. Confirm authentication notifications work.
Configure Passwordless
  1. Open Passwordless Options.
  2. Configure Windows Passwordless.
  3. Select USB Security Key.
  4. Register YK-03.
  5. Configure LastPass Authenticator as the backup authentication method.
  6. Activate.
Generate Recovery OTP
  1. Open Advanced Options.
  2. Manage One-Time Passwords.
  3. Generate Recovery One-Time Password.
  4. Store securely offline.
Validation
  • Windows Passwordless works.
  • LastPass Authenticator works.
  • Microsoft Authenticator works.
  • Face ID works.
  • Master Password works.
  • Recovery One-Time Password stored safely.
📋 Review
  • Decide whether SMS Account Recovery should remain enabled.
  • Configure Emergency Access.
  • Periodically test YK-03 and both authenticator applications.
  • Replace the Recovery One-Time Password immediately if it is ever used.