LastPass
Ploy connects to LastPass using the LastPass Enterprise Provisioning API to keep an up-to-date picture of who has a LastPass account, whether each account is active, who holds admin rights, and whether multifactor authentication is enabled.
The connection is read-only: Ploy syncs data out of LastPass but does not make any changes to your LastPass account.
What Ploy syncs from LastPass
Once connected, Ploy scans LastPass regularly (roughly every hour) and keeps the following in sync:
Users — every LastPass user becomes an identity in Ploy, with their email address, display name, account status (active or disabled), account creation date, and last login time.
Application access — LastPass is added to your application inventory, and each user's access is tracked with their access level (admin or standard user). Disabled accounts are recorded as revoked access.
MFA status — whether each user has multifactor authentication enabled, and which method they use (for example an authenticator app or a hardware key).
Usage — last-login times feed into Ploy's usage insights, so you can see who is actually using LastPass.
Ploy can also look up an individual LastPass user on demand, for example when running offboarding checks for a leaver.
Prerequisites
A LastPass Business account with access to the LastPass Provisioning API.
Admin access to the LastPass Admin Console, so you can find your Account Number and generate a Provisioning Hash.
Step 1 — Find your Account Number (CID)
Your Account Number (sometimes called the CID) identifies your LastPass account to the API.
Sign in to the LastPass Admin Console as an administrator.
Your Account Number is shown on the Admin Console dashboard, labeled Account Number.
Make a note of it — you will enter it in Ploy in a moment.
Step 2 — Generate a Provisioning Hash
The Provisioning Hash is the secret that authenticates API requests for your account.
In the LastPass Admin Console, open the Advanced section and find Enterprise API.
Click Reset Your Provisioning Hash to generate a hash.
Copy the hash and store it securely — treat it like a password.
If you already use the Provisioning API with another tool, be aware that resetting the hash replaces the previous one, so any other tool using the old hash will need to be updated with the new value.
Connect LastPass to Ploy
In Ploy, go to Integrations, find LastPass and click Connect.
Account Number (CID) — enter the Account Number from Step 1 (required).
Provisioning Hash — paste the hash from Step 2 (required).
Click Test to verify the connection, then Save.
Ploy tests the credentials by making a real call to the LastPass API, and the first scan starts automatically once the integration is saved.
Rotating the Provisioning Hash
If you reset your Provisioning Hash in LastPass, reopen the LastPass integration in Ploy, enter the new hash (your Account Number stays the same), then Test and Save again. Your previously saved hash is never shown in the wizard — the field simply indicates that a value is already stored.
Troubleshooting
"Failed to authenticate with LastPass. Please verify your Account Number and Provisioning Hash." — Double-check the Account Number matches the one shown in your Admin Console, and that the Provisioning Hash is the most recently generated one. If the hash has been reset since you connected, the old value no longer works — enter the new hash and save again.
"Connected to LastPass but received an unexpected response. Please contact Ploy support for assistance." — Ploy reached LastPass but the response was not in the expected format. Contact Ploy support and we will investigate.
"LastPass authentication failed. Please check your credentials and try again." — Re-enter both fields carefully and test again.
Users are missing after connecting — the first scan can take a little while on larger accounts. Also note that Ploy syncs users by their LastPass username (email address), so accounts without a username will not appear.