← All playbooks
Security migration

LastPass → 1Password

Move personal and shared vault data from LastPass to 1Password with strict plaintext-export handling, shared-folder permission mapping, passkey and OTP exceptions, credential rotation, cutover, rollback, and evidence that nothing sensitive was left behind.

Typical timeline15–30 business days65–110 hours active work
Statusneeds review
Source testedLastPass export workflow reviewed 2026-07-19
Destination tested1Password LastPass importer guidance reviewed 2026-07-19
Last reviewed2026-07-19
Sources4
Before you migrate

Should you make this move?

Both platforms have a case. Compare what you gain with what you give up before scheduling the cutover.

Current platform

LastPass

Reasons to stay
  • Familiar clients and broad enterprise deployment options reduce adoption friction
  • Centralized credential management improves sharing, recovery, and auditability
Reasons to leave
  • Past security incidents and product trust concerns remain a material decision factor
  • A migration mistake can affect access to every other critical system
New platform

1Password

What gets better
  • Excellent team vaults, passkey support, and polished cross-platform clients
  • Centralized credential management improves sharing, recovery, and auditability
What gets worse
  • Premium pricing and opinionated vault organization may not suit every team
  • A migration mistake can affect access to every other critical system
Best of the move

1Password: Excellent team vaults, passkey support, and polished cross-platform clients. This removes a major source-side concern: Past security incidents and product trust concerns remain a material decision factor.

Worst of the move

What you lose: Familiar clients and broad enterprise deployment options reduce adoption friction. What you inherit: Premium pricing and opinionated vault organization may not suit every team.

01At a glance

Know the shape of the move.

Transfer outcome13 features audited
Transfer outcome distributionClean transfer: 1, Partial transfer: 8, Manual rebuild: 0, Not transferred: 4.
Clean1
Partial8
Manual0
Lost4
Mapping route10 of 12 fields have a destination path

This timeline assumes

  • Profile: one organization with at most 500 users, 100 shared folders, 100,000 items, and managed endpoint access.
  • You control LastPass, 1Password, identity provider, MFA policy, user communications, recovery, security logging, and shared-folder administrators.
  • The 1Password desktop import is preferred; CSV is a break-glass fallback because it creates plaintext secrets.
  • Every LastPass shared folder has an administrator who can import it and a mapped 1Password vault owner.
  • The source stays available during a short read-only verification period, but users stop creating or changing LastPass items at cutover.
02Loss matrix

What survives the move.

“Partial” and “manual” are not footnotes. They are work that must be scheduled and verified.

ItemOutcomeImpactWhat happensMitigation
Login usernames, passwords, URLs, and notescleancriticalThe direct 1Password importer supports core LastPass item data.Reconcile counts by type and test logins across representative URL and credential patterns.
Private folderspartialmedium1Password imports private folders as tags rather than vault hierarchy.Approve a tag taxonomy or separate-vault design before reorganizing.
Shared folderspartialcriticalShared folders can become 1Password vaults, but an administrator and permission-capable destination owner must import them.Import one folder at a time, reconcile item/member counts, and test access before the next.
Shared-folder permissionspartialcriticalPermissions can import with caveats; missing or external users can be omitted and role semantics differ.Use a signed identity/permission map and test effective access with role accounts.
Individually shared itemspartialhighItems import, but sharing relationships and destination organization require review.Place items in approved vaults and re-share through groups rather than ad hoc duplication.
Password historypartialmedium1Password documents password-history import for shared items but not private items.Rotate high-risk credentials and preserve required private history in a controlled archive if policy permits.
Attached filespartialhighFiles attached to supported items can import, while repaired or unsupported records may need manual handling.Compare attachment counts and hashes and review importer repair tags.
TOTP secrets attached to LastPass itemspartialcriticalAttached one-time-password data can import, but every code must be verified against the service.Test current codes and retain recovery codes until confirmation.
LastPass Authenticator OTPslostcritical1Password states that OTPs stored in the separate LastPass Authenticator app do not import.Re-enroll MFA service by service using recovery codes or administrator reset.
PasskeyslostcriticalPasskeys are not imported from LastPass.Inventory passkey-enabled accounts and add a new 1Password passkey before removing the old one.
Form fills, identities, secure notes, and custom item typespartialhighFields and types can map imperfectly; troubleshooting imports may mark repaired items.Review type-specific samples and every item tagged !-repair-items-lastpass.
LastPass MFA, SSO, policies, and emergency accesslostcriticalAuthentication, federation redirects, recovery, policies, trusted devices, and admin controls are not vault items.Configure and test 1Password identity, MFA, recovery, policies, logging, and break-glass access separately.
Item history, audit events, and reportslosthighOperational and compliance history does not become 1Password activity automatically.Export and retain required reports before decommissioning LastPass.
03Field and feature mapping

Where each thing goes.

SourceDestinationMethodNotes
LastPass login1Password Login itemautomaticVerify username, password, URLs, notes, and extra fields.
NameItem titleautomaticResolve duplicate generic titles during review.
URL and extra URLsWebsite fieldsautomaticTest autofill scope and avoid unsafe broad matches.
Private folderTagautomaticIt does not create an access boundary.
Shared folderShared vaultautomaticRequires an approved import administrator and destination ownership.
Shared-folder user/group permissionVault user/group permissiontransformExternal and missing identities require explicit review.
Custom fieldSection fieldtransformVerify concealed/plaintext type, labels, and multiline values.
AttachmentDocument or file attached to itemautomaticCompare binary count and open critical files.
Item TOTP seedOne-time password fieldautomaticConfirm code against the live service before source removal.
LastPass Authenticator OTPNo destinationunsupportedRe-enroll the destination authenticator manually.
PasskeyNo destinationunsupportedRegister a new passkey in 1Password per service.
LastPass policy/SSO/MFA1Password admin, SSO, policy, and recovery configurationmanualBuild and test as a separate control-plane workstream.
04Before you begin

Make the move recoverable.

Backup procedure

Create the source-of-truth backup

Preserve recoverability and audit evidence without creating uncontrolled plaintext copies of the vault.

  1. Inventory users, groups, shared folders, personal item counts, attachments, TOTP items, LastPass Authenticator accounts, passkeys, policies, SSO, MFA, emergency access, integrations, reports, and inactive owners.
  2. Record per-user and per-shared-folder item/type/attachment totals without exposing secret values.
  3. Export required administrative and audit reports into encrypted, access-controlled storage.
  4. Prefer the direct 1Password desktop importer; if CSV is unavoidable, disable cloud backup/sync for the export location and use an encrypted managed device.
  5. Verify recovery codes and break-glass access for services that may require OTP or passkey re-enrollment.

Proof to capture: A signed, non-secret manifest covers every user, shared folder, item type, attachment, MFA/passkey exception, administrator, and recovery owner.

Transformation · LastPass/1Password user and group exports

Identity and vault map

Create destination vaults and least-privilege membership before secrets arrive.

  1. Map users by verified email and status.
  2. Map each shared folder to one vault, owner, groups, and permissions.
  3. Resolve external and departed users before import.

Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.

Transformation · 1Password importer tags and comparison sheet

Repair queue

Prevent importer warnings from becoming silent credential loss.

  1. Collect every !-repair-items-lastpass item and import warning.
  2. Assign an owner and compare against the source.
  3. Do not close a wave with an unexplained repaired or rejected item.

Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.

Transformation · Service inventory and recovery runbook

MFA and passkey re-enrollment

Keep account access while replacing non-portable authenticators.

  1. List LastPass Authenticator OTP and passkey accounts.
  2. Add and test the new 1Password credential using a separate session.
  3. Remove the old factor only after recovery is proven.

Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.

05Handle with care

The things most likely to hurt.

These are operating limits. Treat every “Stop if” condition as a blocked migration, not a suggestion.

Export

A plaintext CSV is copied or backed up

criticalpossible likelihood

The export lands in Downloads, cloud sync, endpoint backup, email, chat, or ticket storage.

Consequence
Every exported secret is exposed in one file.
Mitigation
Use direct import; if unavoidable, isolate, monitor, and securely delete CSV copies immediately.

Stop if: The team cannot prove every plaintext copy location and deletion.

Permissions

Shared-vault access is broader than before

criticalpossible likelihood

A test user can reveal an item outside their source authorization.

Consequence
Privileged credential disclosure.
Mitigation
Import one vault at a time and test effective access before release.

Stop if: Any unauthorized account can view or export a protected item.

Cutover

A non-portable MFA factor locks out users

criticalpossible likelihood

A LastPass Authenticator or passkey-backed service has no tested alternative.

Consequence
Loss of access to production or administrative systems.
Mitigation
Require tested recovery and staged re-enrollment.

Stop if: Any critical service lacks two verified access paths.

Cutover

Users keep changing both vaults

criticallikely likelihood

Modified timestamps advance in LastPass after a user's import.

Consequence
Passwords diverge and users retrieve stale credentials.
Mitigation
Use short waves, freeze writes, and run a final per-user/shared-folder delta review.

Stop if: Source edits cannot be identified and reconciled.

Identity

SSO or MFA redirects block 1Password access

criticalpossible likelihood

Pilot users loop, cannot unlock, or cannot recover on a second device.

Consequence
Organization-wide vault outage.
Mitigation
Pilot identity configuration and maintain break-glass owners outside the failing path.

Stop if: Recovery and second-device enrollment do not pass.

06Precise timeline

Do the work in this order.

Estimate forUp to 500 users, 100 shared folders, and 100,000 items
Total elapsed15–30 business days
Active work65–110 hours
BufferAdd 1–2 weeks for missing shared-folder admins, external users, SSO changes, LastPass Authenticator migration, passkeys, or high-risk credential rotation.
01
Days 1–4Inventory and security design4 days
02
Days 5–7Configure destination controls3 days
03
Days 8–11Pilot users and shared vaults4 days
04
Days 12–20User and folder waves5–9 days
05
Days 21–23Write freeze and control switch1–3 days
06
Days 24–30Read-only verification and rotation5–7 days
  1. Days 1–4 · inventory

    Inventory and security design

    16–24 hours active4 days elapsedOwner and security approval waiting
    • Inventory vault data, identities, sharing, MFA/passkeys, policies, recovery, and integrations.
    • Design 1Password accounts, groups, vaults, SSO, MFA, recovery, logging, and waves.

    Depends on: Admins for both products, IdP, security, and shared-folder owners

    Stop / go checkpoint

    Approve pilot?

    Go when: Every folder, identity, exception, and critical recovery path has an owner.

    Stop when: A critical shared folder has no admin or service has no recoverable MFA path.

  2. Days 5–7 · configure

    Configure destination controls

    10–16 hours active3 days elapsedIdentity propagation waiting
    • Configure SSO/MFA, groups, vaults, policies, logging, recovery, and managed apps.
    • Test break-glass, second-device enrollment, and offboarding.

    Depends on: Approved design

    Stop / go checkpoint

    Import secrets?

    Go when: Identity, recovery, access, logging, and endpoint controls pass without vault data.

    Stop when: A normal or break-glass user cannot enroll, unlock, recover, or be removed safely.

  3. Days 8–11 · pilot

    Pilot users and shared vaults

    12–18 hours active4 days elapsedUser and service-owner testing waiting
    • Import representative personal and shared data with the desktop importer.
    • Review repairs, attachments, TOTP, autofill, permissions, and recovery.
    • Re-enroll pilot passkeys and external authenticator accounts.

    Depends on: Destination controls, Approved pilot cohort

    Stop / go checkpoint

    Approve waves?

    Go when: Counts, access, login, TOTP, recovery, and secure cleanup pass.

    Stop when: A secret is missing, exposed, wrongly shared, or locks out a critical service.

  4. Days 12–20 · waves

    User and folder waves

    18–34 hours active5–9 days elapsedUser imports and owner verification waiting
    • Import users and shared folders in small owner-led waves.
    • Reconcile every wave, repair items, and re-enroll non-portable MFA/passkeys.
    • Rotate privileged credentials by risk tier.

    Depends on: Approved pilot, Support coverage

    Stop / go checkpoint

    Schedule final freeze?

    Go when: Every user/folder is verified or has an approved exception and critical factors are re-enrolled.

    Stop when: Repair queues, access errors, plaintext exports, or lockout risks remain.

  5. Days 21–23 · cutover

    Write freeze and control switch

    5–9 hours active1–3 days elapsedIdentity and device refresh waiting
    • Freeze LastPass changes and reconcile final deltas.
    • Switch SSO, browser extensions, policies, helpdesk, onboarding, and integrations to 1Password.
    • Restrict LastPass and monitor access.

    Depends on: Completed waves, Communication plan

    Stop / go checkpoint

    Make 1Password authoritative?

    Go when: No unexplained delta, critical access works, and LastPass cannot receive normal user writes.

    Stop when: Any privileged secret, MFA factor, or recovery path is unverified.

  6. Days 24–30 · observe

    Read-only verification and rotation

    4–9 hours active5–7 days elapsedNormal login use and user feedback waiting
    • Monitor sign-in, recovery, access, autofill, TOTP, service accounts, and helpdesk cases.
    • Finish privileged rotation and complete the verification report.

    Depends on: Successful cutover

    Stop / go checkpoint

    Close rollback window?

    Go when: Blocking checks pass, users and owners sign off, and high-risk credentials are rotated.

    Stop when: A source-only secret or factor is still required.

07The point of change

Cut over with a way back.

Go live

Cutover

Make 1Password the only writable credential system after reconciling final LastPass changes and verifying recovery.

Recommended window: Tuesday or Wednesday morning with security, identity, helpdesk, and service owners staffed for the next two business days.

  1. Announce the exact LastPass write-freeze time and staffed support window.
  2. Identify and reconcile items changed since each wave imported.
  3. Complete critical LastPass Authenticator and passkey re-enrollment.
  4. Switch SSO redirects, extensions, managed-app settings, onboarding, helpdesk, and integrations.
  5. Restrict normal LastPass access without deleting data.
  6. Run privileged-login, TOTP, shared-vault, new-device, recovery, and offboarding tests.

Proof to capture: No unexplained delta remains; critical credentials and factors work; least-privilege vault access, recovery, and logging pass; and LastPass is read-only.

Return to safety

Rollback

Restore controlled LastPass use without discarding credentials changed in 1Password after cutover.

Deadline: Within 24 hours for identity or privileged-access failures and before broad password rotation makes reverse reconciliation impractical.

  1. Freeze 1Password item edits and record every changed item since cutover without exporting secret values broadly.
  2. Restore the previous SSO, browser-extension, and LastPass access configuration.
  3. Have item owners apply reviewed new credentials and TOTP changes back to LastPass individually.
  4. Retest critical access and recovery from a clean session.
  5. Keep 1Password restricted and preserve logs for reconciliation.

Proof to capture: LastPass again provides verified critical access and recovery, contains every approved post-cutover credential change, and 1Password writes are frozen.

Rollback immediately when
  • Critical account lockout
  • Unauthorized shared-vault access
  • Unexplained missing or corrupted secrets
  • Organization-wide SSO/MFA failure
  • Uncontained plaintext export exposure
08Verification report

Prove the migration worked.

Every blocking check must pass. Capture the evidence before cleanup begins.

0%
Interactive report preview0 / 8 checks passed
PassIDCheckMethodExpected resultEvidence
V-01BlockingItem and type reconciliationCompare per-user and per-shared-folder counts by item type without exposing values.Every item is imported, repaired, archived, or explicitly excluded.Signed non-secret reconciliation.
V-02BlockingVault permissionsTest owner, member, group, external, departed, and unauthorized accounts.Only approved identities can reveal, edit, manage, or export each vault.Effective-access test matrix.
V-03BlockingRepresentative logins and autofillTest critical, multi-URL, subdomain, duplicate-name, and custom-field items.Correct item is suggested and authenticates without exposing it to unrelated sites.Service-owner login log.
V-04BlockingAttachment integrityCompare counts and hashes and open every critical attached file.All required binaries are intact and associated with the correct item.Attachment manifest.
V-05BlockingTOTP and passkey dispositionTest imported item TOTPs and every manually re-enrolled LastPass Authenticator/passkey service.Current codes/passkeys work and each critical service retains a tested recovery path.MFA migration ledger.
V-06BlockingSSO, new device, recovery, and offboardingRun full scenarios with pilot and break-glass accounts.Users enroll, unlock, recover, and lose access according to policy.Identity scenario log.
V-07BlockingImporter warningsReview every failed, skipped, duplicate, or !-repair-items-lastpass item.No unexplained repair or rejected item remains.Repair queue export.
V-08BlockingPlaintext export eradicationInspect managed endpoints, backups, sync folders, downloads, tickets, and collaboration systems used during migration.No CSV/plaintext vault copy remains; deletion evidence is recorded.Secure-handling checklist and endpoint evidence.
09Post-migration cleanup

Remove the scaffolding safely.

Safe after: At least 14 days, all users and shared-folder owners sign off, high-risk credentials are rotated, and all blocking checks pass.

  1. Preserve only approved encrypted reports, manifests, mappings, and verification evidence; do not retain plaintext vault exports.
  2. Securely delete CSVs and temporary exports from endpoints, backups, sync, tickets, and collaboration systems.
  3. Revoke LastPass sessions, API keys, app integrations, emergency access, and temporary administrator permissions.
  4. Rotate privileged, shared, service-account, recovery, and any potentially exposed credentials.
  5. Retain LastPass in restricted read-only form only through the approved compliance window, then follow formal decommissioning.
  6. Schedule quarterly access, recovery, secret-health, dormant-user, audit-log, and plaintext-export control reviews.
10Experiences from the field

When the plan met reality.

First-hand accounts are preferred. Vendor case studies are labeled, and every note below is an editorial paraphrase—follow the link for the full context.

First-person accountr/1Password

1Password as alternative to LastPass

Several people who had moved from LastPass describe a short adjustment period followed by equal or better everyday autofill, particularly on mobile. One contributor highlights storing time-based one-time-password tokens in 1Password so browser logins can fill the second factor. The discussion also makes clear that successful importing does not eliminate the need to learn different interaction patterns.

What they recommend
  • Allow a few days of overlap to learn the new autofill behavior across desktop browsers and mobile applications.
  • Test important two-factor logins and decide whether authenticator tokens should move into 1Password or remain separate.
Worth noticing
  • Import completion was only the first milestone; adapting to the destination’s daily behavior took several days.
  • Integrated one-time-password support was a meaningful workflow improvement for some people leaving LastPass.

A recent switcher reports that the LastPass-to-1Password migration completed very quickly and recommends performing both the LastPass export and 1Password import through their web interfaces. The account is brief but useful as a concrete implementation detail: using matching browser-based flows avoided the friction the author expected from moving an entire password vault.

What they recommend
  • Use the documented web export and web import path, then inspect the imported vault before changing or deleting the source.
  • Keep the export file protected and remove it securely only after item counts and critical logins have been verified.
Worth noticing
  • For this personal vault, the mechanical transfer was substantially faster than expected.
  • The author’s most actionable tip was to use the web interfaces on both sides of the transfer.
Sources and maintenance

Built to be reviewed.

Tested 2026-07-19. Next scheduled review: 2026-10-19.

  1. 1Password: import from LastPassAccessed 2026-07-19
  2. 1Password: LastPass import troubleshootingAccessed 2026-07-19
  3. 1Password: import CSV and export safetyAccessed 2026-07-19
  4. LastPass: export vault data as CSVAccessed 2026-07-19