Videos
Safari 16.5.2, MacOS 13.4.1c, LastPass 4.118.0
I am able to login to Lastpass on the web, but even though I'm logged in to the website, the Safari LP Extension wants me to login. when I try to login it just gives me the spinning safe graphic then after a while reverts back to a login screen asking me again for my Master Password. I've tried enabling passwordless login which doesn't do anything with the extension login issue. I've disabled the extension and reenable it, I've restarted Safari. I've reinstalled LastPass. nothing fixes this for me. The LastPass extension just doesn't seem to work anymore in Safari.
Any ideas?
In Safari I can login to LastPass and it works fine. Then a little while later it goes grey and says "Login" but when I click on that it opens the LastPass app and it's logged in already. I cannot fill passwords or get logged into the extension . It works fine in Chrome on the same Mac but Chrome uses a lot more battery so I want to stay with Safari.
Just got a new Mac Air - it's my first apple computer after mostly leveraging windows laptops from work.
I set up Lastpass by downloading Lastpass for Safari extension in the App Store, and followed instructions so it allowed autofill in setting.
However, instead of autofilling username and password on a site, a dialogue box opens up on the top left that prompts me to start typing.
Not sure what it wants me to type, but even typing the username I know I use for the site I am trying to get autofill to work on doesn't trigger autofill. I had entered my username and password manually the first time, but the next time I went to the site it wasn't autopopulating. I tried closing down the browser and restarted it, closed down my mac and restarted, even trashed the extension and redownloaded it again. None of this caused the autofill feature to just work.
It looks like I am signed into Lastpass correctly - the redbox with dots appears both in the username/password fields, as well as in the toolbar. It simply isn't autopopulating and nothing I do with this weird dialogue box prompting me to "start typing" gets me to the experience of having my vault simply autopopulating the info.
Anyone come across this and can suggest a fix?
Super frustrating, making me wonder why I switched to Mac in the first place - I thought the OS and interfaces was "just supposed to work"!
I'm also in a very similar situation. I suspect your assumption here is correct:
"My assumption is the iOS app is using an embedded Safari browser that for some reason can't play with Conditional Access"
I can see the sign request coming form:
Browser: Mobile Safari 16.2
Operating System: iOS 16
however, no Device ID is displayed.
Going deeper into troubleshooting:
The device is clearly joined and compliant, it was confirmed in Intune and by looking up the device info.
Now I wonder what's stopping Safari to pass the Device ID onto the auth flow?
**For those stumbling upon this discussion:
The issue of the in-app browser (Safari) not communicating Device ID with CA was resolved by deploying the following configuration profile:**
[https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-ios-ipados-macos
Enterprise SSO plugin resolved our issue and I successfully authenticated with a compliant iPad based on device ID/compliance.
The problem lies in the fact that many apps, specially on iOS, relies on embeded browser (usually safari) to authenticate users. So if you have App Protection policy with the enforcing conditional access policy (Require Approved Apps and Require App Protection Policy), conditional access will force you to use edge. As soon as you open edge then you fall on a CSRF error because the token cannot be ported to another app.
The bottom line is that App Protection cannot work with Safari and apps that rely on this cannot go through App Protection policy (if enforced). The only way to get this to work is to litteraly exclude users from the conditional access policies that enforces App Protection (and open a big hole in your security posture that can and most likely will, be exploited).
I’m in some identity management pain. I don’t recall opting into passkeys but somehow Google is now asking me for it when I’m using them for id management. I don’t think i have a passkey. When i try to create one, LastPass says “Password can’t be added.” (I’m not trying to use Lastpass, it’s just inserting itself.)
I see another thread on this topic but am not finding Lastpass to be buggy. The issue is more that either passkeys are not ready for prime time or they’re not playing nicely with last pass.
Should I turn off LastPass? Turn off passkeys? (How?)
I’ve also noticed google 2fa doesn’t work when things are launched from Facebook. (Not sure if it’s a security issue or a bug.)
Has anyone found a way out of this mess while keeping LastPass?
Thanks