setup

LastPass Enterprise

Purpose

Imports vault inventory, shared folders, and user assignments from LastPass Enterprise.

tip

Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.

important

The LastPass provisioning API is only accessible from allow-listed IPs. Set tailscale_hostname and run the collector from a SubImage Outpost inside that network.

Required Fields

Field Secret? Description
lastpass_cid No Company ID provided by LastPass
lastpass_provhash Yes LastPass Provisioning Hash
tailscale_hostname No (Optional) Internal hostname resolved via Outpost

Setup Steps

  1. In the LastPass Admin Portal → Advanced → Enterprise API, retrieve the CID and ProvHash.
  2. In SubImage, fill in lastpass_cid, lastpass_provhash (or its AWS Secret ARN), and — if using Outpost — tailscale_hostname. Save the module.