Videos
Safari 16.5.2, MacOS 13.4.1c, LastPass 4.118.0
I am able to login to Lastpass on the web, but even though I'm logged in to the website, the Safari LP Extension wants me to login. when I try to login it just gives me the spinning safe graphic then after a while reverts back to a login screen asking me again for my Master Password. I've tried enabling passwordless login which doesn't do anything with the extension login issue. I've disabled the extension and reenable it, I've restarted Safari. I've reinstalled LastPass. nothing fixes this for me. The LastPass extension just doesn't seem to work anymore in Safari.
Any ideas?
In Safari I can login to LastPass and it works fine. Then a little while later it goes grey and says "Login" but when I click on that it opens the LastPass app and it's logged in already. I cannot fill passwords or get logged into the extension . It works fine in Chrome on the same Mac but Chrome uses a lot more battery so I want to stay with Safari.
I thought this would be more prevalent, but I searched here and saw no other post on this..
As described on title, starting from v 4.94.0 I only get a blank window when trying to access password via the safari extension, this basically makes last pass useless on this browser. I tried following instructions here: https://support.lastpass.com/help/how-do-i-troubleshoot-or-uninstall-the-lastpass-for-safari-app-extension-lp010142
and it did not help. I also tried uninstalling last pass and starting from scratch, that did not help either.
Has anyone figured out how to resolve this?
Thanks.
I'm also in a very similar situation. I suspect your assumption here is correct:
"My assumption is the iOS app is using an embedded Safari browser that for some reason can't play with Conditional Access"
I can see the sign request coming form:
Browser: Mobile Safari 16.2
Operating System: iOS 16
however, no Device ID is displayed.
Going deeper into troubleshooting:
The device is clearly joined and compliant, it was confirmed in Intune and by looking up the device info.
Now I wonder what's stopping Safari to pass the Device ID onto the auth flow?
**For those stumbling upon this discussion:
The issue of the in-app browser (Safari) not communicating Device ID with CA was resolved by deploying the following configuration profile:**
[https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-ios-ipados-macos
Enterprise SSO plugin resolved our issue and I successfully authenticated with a compliant iPad based on device ID/compliance.
The problem lies in the fact that many apps, specially on iOS, relies on embeded browser (usually safari) to authenticate users. So if you have App Protection policy with the enforcing conditional access policy (Require Approved Apps and Require App Protection Policy), conditional access will force you to use edge. As soon as you open edge then you fall on a CSRF error because the token cannot be ported to another app.
The bottom line is that App Protection cannot work with Safari and apps that rely on this cannot go through App Protection policy (if enforced). The only way to get this to work is to litteraly exclude users from the conditional access policies that enforces App Protection (and open a big hole in your security posture that can and most likely will, be exploited).
I’m in some identity management pain. I don’t recall opting into passkeys but somehow Google is now asking me for it when I’m using them for id management. I don’t think i have a passkey. When i try to create one, LastPass says “Password can’t be added.” (I’m not trying to use Lastpass, it’s just inserting itself.)
I see another thread on this topic but am not finding Lastpass to be buggy. The issue is more that either passkeys are not ready for prime time or they’re not playing nicely with last pass.
Should I turn off LastPass? Turn off passkeys? (How?)
I’ve also noticed google 2fa doesn’t work when things are launched from Facebook. (Not sure if it’s a security issue or a bug.)
Has anyone found a way out of this mess while keeping LastPass?
Thanks