02-26-2021 09:49 AM
Seems like the Duo integration on lastpass, isnt working.
Today I enabled Duo on my lastpass, without issues, then I logged out…when I tried to log in again…nothing!, just the error “Multifactor authentication failed”, I had also google authentication working for a long time, so I tried to clic the option to use another authentication with the “Additional Multifactor options”, but get instantly redirected to the login with the “Multifactor authentication failed”. Lastpass support asked me to reset the account, I had a backup so I did it, but…still asked for Duo and instant error.
Some one had this issue before? If I delete the app from my Duo account, lastpass will switch to gauth or will make things worst?
Same problem on Brave,Firefox, Chrome, Safari (all on osx) and iphone
The Error
The prompt that redirects
02-26-2021 10:25 AM
Hi @Manuelflores51,
I’m very sorry to hear you are having issues logging into LastPass.
Duo for LastPass is functional; I just logged into my Duo-protected LP account with Duo Push on macOS+Chrome and Android+LastPass app to double-check.
Did the Duo MFA option ever work for you, or is this your very first login after configuring Duo? If this is the first try, is it possible that the Duo integration information was entered incorrectly?
If you contact Duo Support they can examine logs from the Duo 2FA attempt to see if the issue is on the Duo side.
However, Duo Support does not have the ability to restore access to LastPass or change your Duo configuration within LastPass. Only LastPass support could do that.
Edited to ask this question: have you enrolled your LastPass username in Duo? Did you step through the Duo enrollment process where you added a phone to the user, or added a phone to the user from the Duo Admin Panel?
02-26-2021 12:08 PM
I created a Duo admin account
Downloaded the app
Activated Duo Push (was asked for phone number,type of phone,etc)
Logon to the admin page
Duo push worked without issues to enter admin area
Went to the Applications page list
Selected lastpass
Click Protect this Application
Got integration key , secret key , and API hostname
Went lo lastpass vault
Account Settings
Multifactor
Duo
copied and pasted integration key , secret key , and API hostname
Enabled Select Yes .
Permit Offline Access Set to Allow
Use Duo Web SDK when possible No
Put master password
Enroll window
Enter duo username (admin mail)
Same as Two-Factor Authentication for LastPass | Duo Security except SDK to no
I can access my Duo admin panel without problem with push. But lastpass dont letme enter a code or send a push, just redirects to error message.
02-26-2021 01:46 PM
Hacked myself into my lastpass to fix this, seems like the secret key was incorrect.
Setup burp proxy to intercept the login, and that gave me time to change the 2fa option to google authenticator, logged into the account, disabled Duo, deleted the app from my admin portal on duo, added again the app, then enabled it again on lastpass, and now it is working, thank you!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide