

Bitwarden: CNET's top password manager is a highly secure and open-source LastPass alternative.If everything is correct you should get an authentication request on your phone. LastPass will verify you username and key. An authentication request will be send to LastPass through the LastPass MFA tree. LastPass MFA tree will search for user email (mail or email attribute) in the data store if email is empty an email address will be generated from user DN.

You can test the LastPass MFA authentication tree by accessing this URL in your browser HERE/openam/XUI/?realm=/#login/&service=LastPass.Select the Retry Decision Limit and set the Retry Limit to 15.Add a Retry Decision Limit node and connect it as shown in the image below.Select the Polling Wait Node and set Seconds To Wait to 4.Select the LastPass Service Decision node and set the following URL in Login Token Endpoint.Add 3 nodes: Polling Wait Node, LastPass Service Decision and Success and connect them as shown in the image below.If you leave it as Default then the Authentication Method will be the one selected by users on their phone. Select the Authentication Method you'd like to use.Set the following URL in Authentication Endpoint. Paste the key value from step 4 on LastPass MFA Key. Select the LastPass Service Initiator node and set the LastPass MFA Key.Connect them as shown in the image below.Add 4 tree nodes: Start, Username Collector, LastPass Service Initiator and Failure.Login into AM console as an administrator and go to Realms > Top Level Real > Authentication > Trees.

Copy the LastPass MFA Login value by clicking in the green button and save it for later.
