We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Bundle guide · Webroot, OpenText, LastPass and CISA documentation checked August 6, 2026

Webroot Total Protection backup and LastPass: the limits that matter

The bundle can protect five or ten devices, but its “unlimited” cloud backup covers one computer. The password manager is a separate LastPass service with its own account, recovery rules and security history. Here is how to set up both without discovering those boundaries during a crisis.

One-computer limit verifiedRestore test includedLastPass boundary explainedNo inferred seats

Quick answer: Total Protection is a coherent bundle only if one PC or Mac holds the household's most important files. “Unlimited” refers to storage on that one computer, not the number of protected devices. Backup + Restore is based on Carbonite Safe; Password Manager is powered by LastPass. Activate, test and secure them separately, then keep an offline file copy and an independent vault-recovery plan.

Quick verdict: useful coverage with two easy-to-miss boundaries

The current Webroot Total Protection page makes the first boundary explicit in a footnote: automatic backup with unlimited storage is limited to one PC or Mac. That remains true whether the antivirus side protects five devices on the individual plan or ten devices on Family.

The second boundary is architectural. OpenText describes Backup + Restore as a white-labelled Carbonite Safe service and the password manager as LastPass. The Webroot dashboard can launch them, but their clients, accounts, status and recovery paths remain distinct. A working antivirus subscription doesn't prove that a file completed upload or that a LastPass account can be recovered.

This isn't necessarily a bad arrangement. One off-site backup can be valuable, and a dedicated password manager is better than reusing credentials. The trouble starts when bundle language lets a household assume every laptop is backed up or every family member automatically receives a vault.

Use the plan if its exact entitlement matches the household. Assign the backup license to one named computer, inspect what was selected, perform a real restore and secure the LastPass account separately. Keep a second recovery route outside both services.

Current Total Protection plans, prices and entitlements

When checked August 6, 2026, the US page showed Total Protection at $107.99 for the first year and $179.99 as the regular annual price. It covers five devices, one identity, VPN on five devices and unlimited cloud backup for one PC or Mac. Our Webroot pricing guide separates first-year offers from the renewal cost, while the plan comparison maps the rest of the bundle.

Total Protection Family showed $179.99 for the first year and $299.99 regular. It covers ten devices and ten identities. The backup allocation doesn't grow with those counts: an OpenText product release note says customers receive one license for unlimited backup of a device through Webroot Backup + Restore.

QuestionTotal ProtectionTotal Protection FamilyWhat to verify
Antivirus devices510Actual device list in MyAccount
Identity monitoring1 identity10 identitiesEnrollment completed for each person
Cloud backup1 PC or Mac1 PC or MacNamed computer and completed first backup
Password managerLastPass feature listedLastPass feature listedActual account entitlement shown in MyAccount
Regular annual price checked$179.99$299.99Checkout, taxes and renewal notice

The current page lists a password manager but doesn't clearly publish how many LastPass accounts each plan provisions. Device and identity counts belong to different services; they aren't evidence of LastPass seat counts. Check the live account before moving a family’s credentials.

What Webroot built—and what it hands to Carbonite and LastPass

OpenText’s Total Protection announcement combines device security, identity protection, VPN, parental controls and cloud backup under one subscription. That's a billing and launch experience, not one technical engine. The Secure VPN review and identity protection review test those separate layers without confusing them with file recovery.

The current Webroot Application panel lists Backup + Restore and LastPass Password Manager on Windows and macOS. It sends users to a download or online account flow for the separate application. The mobile security guide likewise says Password Manager is powered by LastPass and opens the appropriate app store.

Backup + Restore isn't the old SecureAnywhere Backup & Sync feature, and it isn't OneDrive or iCloud. Sync services are designed to keep a working state aligned across devices; deletion or encryption can propagate. A backup service is designed to retain recoverable copies, but its retention and selection rules still matter.

The LastPass vault isn't inside Webroot’s antivirus database. Webroot can't reveal a forgotten LastPass master password, and a Webroot renewal doesn't replace LastPass recovery preparation. Treat each service as a separate dependency even when a single subscription launches both.

Set up backup and password management before you need recovery

The useful moment to learn this bundle is while the computer and accounts are healthy. The workflow below deliberately includes entitlement verification, a restore test and an exit plan; simply installing two apps doesn't prove recoverability.

  1. Verify the exact entitlement

    Open Webroot MyAccount and confirm that Backup + Restore and LastPass appear for this subscription. Record which computer owns the single backup license; don't infer password-manager seats from device or identity counts.

  2. Install Backup + Restore on the chosen computer

    Use the Webroot Application panel or MyAccount download, name the computer clearly and choose automatic or reviewed advanced selections. Install it only on the PC or Mac that holds the files the household can't replace.

  3. Review every selected folder

    Confirm Desktop, Documents, Downloads, Music and Pictures, then manually inspect videos, files outside the normal user folder, large files, external drives and application-created backup files.

  4. Finish and verify the initial backup

    Keep the computer awake and online until the application reports completion. Check several known files in the backup view instead of trusting a green status alone.

  5. Restore a disposable test file

    Create and back up a small test document, delete or change the local copy, then restore it to a separate location and open it. Record the date and repeat this test periodically.

  6. Activate the LastPass service separately

    Launch Password Manager from the Webroot Application panel and follow the LastPass account handoff. Confirm the actual account entitlement before importing or deleting credentials elsewhere.

  7. Secure the vault and recovery path

    Create a long unique master password, enable MFA, review recovery options and store the recovery material outside the vault. Verify the current account security settings before moving important logins.

  8. Keep an independent exit and recovery copy

    Maintain an offline or otherwise separate backup of critical files and a protected password-manager export or migration plan. A bundled subscription shouldn't be the only route back to both files and accounts.

Eight-step Webroot backup restore test and LastPass MFA recovery workflow
Verify both entitlements, prove one file can be restored and keep recovery information outside the same vault.

Use a disposable document for the first restore. A family photo or current work file shouldn't be the experiment. Record what was restored, where it appeared and whether the application could open it.

Automatic backup is a starting selection, not a complete inventory

On Windows, Webroot’s installation guide offers automatic settings or advanced selection. Automatic mode starts with normal user data, while advanced mode can begin with the defaults or nothing selected.

The more precise file-selection guide identifies Desktop, Documents, Downloads, Music and Pictures as the automatic folders. That covers many households, but folder names aren't proof that every important file lives there.

Build a short inventory before the initial upload. Check accounting exports, email archives, browser downloads, creative projects, local game saves, scanner folders, photo catalogs and files created by specialist applications. Confirm their actual paths rather than assuming “Documents” catches them.

On a Mac, use the matching Mac guidance because selection rules and filesystem permissions differ. Don't copy a Windows click path into macOS. In both cases, inspect the online or application view after the first run and locate several files by name.

Videos, large files, external drives and databases need attention

Webroot says videos aren't automatically selected. Files outside C:\Users, files larger than 4 GB other than PST files, and external or network drives may also need manual selection. “Unlimited storage” doesn't make an unselected file appear in the backup.

An external drive deserves two decisions. First, verify that its data is supported and selected. Second, decide whether that drive is itself the independent offline copy. Leaving it attached all the time makes it accessible to malware and accidental deletion; using the same drive as both source and resilience layer weakens recovery.

Live databases are a harder boundary. Webroot’s database guidance says SQL, Exchange, Access and similar live databases aren't supported at file level because a consistent point-in-time restore must preserve related files together.

Use the database software to create its own supported backup file on a schedule, verify that file, then select it for cloud backup. Do the same for any application that documents an export or backup command. Copying an open data folder isn't equivalent to a recoverable application backup.

Backup timing: green status is useful, but it isn't a recovery test

The initial upload can take hours or days depending on data volume and upstream speed. Keep the chosen computer powered, awake and connected. Pause large competing uploads if they make the machine unusable, but don't assume a partial backup is complete because the client is installed.

Webroot’s version documentation says frequently changed files are backed up at most once every 24 hours. This isn't continuous replication for a database, active project or transaction stream. A file created and lost between backup passes may never reach the cloud.

Inspect the client’s last backup time, pending file count and errors. Then locate known files in the backup. Status should answer three questions: when did a successful pass finish, which items remain pending and which files were skipped?

Schedule a monthly five-minute check and a periodic test restore. This is more useful than watching the backup icon daily because it tests the output, not only the process.

Version history and the 30-day retention clock

On Windows, Webroot documents up to 12 versions: one daily version for each day of the past week, one weekly version for each of the prior three weeks and one monthly version for each of the previous two months. It also says at least the original and two most recent versions are retained when available.

“Up to” matters. A computer that was off, a file that wasn't selected or a backup that had not completed can't create the theoretical schedule. Webroot also retains only the latest filename record, so renaming behavior can complicate finding older content.

Webroot support says data remains for 30 days after subscription expiration. Its computer-transfer guidance applies a similar 30-day window to files no longer present or restored when a subscription moves. Those clocks are recovery buffers, not an archive policy.

Renew or migrate before the deadline. If the subscription will end, restore important data while the account and original machine are still available. Verify file counts and open representative restored files before considering the migration finished.

Restore one file now; learn Recover Mode before a large recovery

The Search and Restore guide can restore to the original location or a folder on the desktop. Restoring over the original can overwrite it, so the first test should use a separate location. Open the restored file and compare its contents, not just its filename.

Recover Mode pauses new and changed-file backup while data is missing or being restored. That prevents the damaged or empty local state from immediately becoming the new cloud state. It's especially important after disk repair, a computer move or broad accidental deletion.

The pause isn't self-explanatory: Webroot says backup won't resume until Recover Mode is exited. After recovery, review the restore report, confirm the needed files are present, exit the mode and verify that a new backup completes.

Web access is convenient for a handful of files. Use the application and documented transfer workflow for large or full recovery. A browser download of a few photos doesn't prove that a whole user profile can be rebuilt.

Cloud backup helps with ransomware, but it isn't the whole 3-2-1 plan

Off-site versions can recover files after local hardware loss or encryption. They don't make the account, computer or backup client immune to compromise. An attacker with device or account access may delete files, steal session data or interfere with restore work.

CISA’s ransomware guidance recommends offline, encrypted backups and regular tests of availability and integrity. CISA specifically warns that accessible backups are targets. Keep another copy disconnected or otherwise isolated from the everyday computer and its credentials.

A practical household version of 3-2-1 is the working copy, Webroot’s off-site copy and an encrypted external drive that's disconnected after backup. The critical data should exist on at least two media types or failure domains, with one copy off site.

Cloud backup also doesn't replace antivirus or incident response. If malware is active, isolate and clean the device before reconnecting recovery media. Restore data only after the system is trustworthy enough not to encrypt the recovered copy again.

LastPass activation is a separate service handoff

The Application panel says Password Manager directs the user to an online account to download LastPass. Webroot’s mobile guide similarly opens Google Play or Apple’s App Store. Expect a LastPass app, extension and account flow rather than a vault inside Webroot.

Start from the signed-in Webroot account, not a search ad or unsolicited support link. Confirm which email receives the entitlement and whether an existing LastPass account can use it. Don't delete the old password store until the new vault opens on a second trusted device and important entries work.

The public Total Protection page doesn't clearly state how many LastPass accounts Family receives. If the Application panel exposes only one activation or the account emails don't match, capture the plan name, order and entitlement screen before contacting official support.

Keep billing ownership clear. Webroot controls the bundle subscription; LastPass controls vault access and its client. A renewal delay can affect entitlement while a forgotten master password is a different recovery problem.

Secure the vault: master password, MFA and recovery outside LastPass

LastPass describes a zero-knowledge design in which the encryption key is derived from the master password and sensitive vault data is decrypted on the user’s device. That makes the master password both powerful and unforgiving: LastPass can't simply reveal it.

Create a long, unique master password that has never protected another account. Enable MFA and save recovery options before importing the only copy of important credentials. Store recovery material in a protected place outside the vault; putting the only emergency key inside the locked vault creates a circular recovery plan.

Review the account’s current security settings. LastPass says its current system uses 600,000 PBKDF2-SHA-256 iterations, but existing accounts should still verify what their security dashboard reports. Don't publish or email a vault export unencrypted.

A password manager reduces password reuse and can generate unique credentials. It can't make a compromised computer safe or stop a user from approving a malicious login. Keep the device patched, review autofill destinations and protect the email account used for recovery.

The 2022 LastPass incident belongs in the buying decision

LastPass’s official March 2023 incident update says an attacker used information from an earlier development-environment incident to target a DevOps engineer and access cloud backups. The accessed data included encrypted and unencrypted customer data.

LastPass says master passwords weren't stored and sensitive vault data was protected by its zero-knowledge model, with some metadata outside that encrypted boundary. The practical risk depended heavily on the strength and uniqueness of each user’s master password and the account’s key-derivation settings.

Its current security page says it rebuilt core infrastructure, strengthened access controls, increased PBKDF2 iterations and completed additional assessments. Those are relevant improvements; they don't erase the need to consider the incident and the service’s trust model.

The reasonable choices aren't blind confidence or panic. A user who accepts the model should harden the account, maintain recovery and retain a migration path. A user who doesn't accept it should choose another password manager before moving credentials—not leave passwords reused in browsers or notes.

When activation, subscription dates or restores don't work

If Backup + Restore reports “Subscription Date is Invalid” after startup, Webroot says the client may not yet have connected to its server. Its official resolution is to wait briefly, restart, then reinstall Backup + Restore if the error persists. New or renewed entitlements can take several hours to appear.

Don't remove the antivirus just because the backup client has a problem. Capture the Webroot account email, plan, renewal date, computer nickname, last successful backup and exact error. Reinstall the separate Backup + Restore application only after confirming no restore is currently running.

If files seem missing during recovery, enter Recover Mode before allowing a new backup state to settle. Search by filename and extension, inspect the restore report and use the computer-transfer workflow for a repaired or replacement Windows PC.

For LastPass activation, separate entitlement from vault access. A missing Webroot launch tile is a subscription-provisioning issue; a rejected LastPass master password or MFA challenge belongs to LastPass recovery. The Webroot account guide covers account and device ownership, while the general troubleshooting guide covers wider application failures.

Who gets value from the bundle—and who should split the services

Total Protection fits an individual with several devices but one main computer that holds the important files. It also suits a family whose shared archive lives on one desktop or Mac and whose members are willing to verify password-manager access rather than infer it from the plan name.

The Family price is harder to justify when irreplaceable files are distributed across several laptops. Only one computer receives Webroot cloud backup, so the household must buy or configure additional backup coverage anyway. Compare the total renewal cost, not just the first-year discount.

Existing customers should also inspect overlap. The bundle may duplicate an established cloud backup, VPN or password manager. Consolidation is valuable only when the new service is at least as recoverable and the migration is completed safely.

Our bottom-line test is simple: if one named computer, one verified backup entitlement and the actual LastPass account allocation match the household, the bundle is convenient. If those facts don't line up, separate best-fit services are clearer than paying for a package whose most important limits appear during setup.

Webroot Total Protection backup and LastPass FAQ

Does Webroot Total Protection include unlimited cloud backup?

Yes, but unlimited describes storage volume for one PC or Mac. It doesn't mean unlimited computers, every file type or every device covered by the antivirus subscription.

How many computers can Webroot Total Protection back up?

One PC or Mac. OpenText also describes Total Protection Family as receiving one backup license, so the family plan doesn't expand cloud backup to ten computers.

What files does Webroot back up automatically on Windows?

Automatic selection covers Desktop, Documents, Downloads, Music and Pictures under the normal user profile. Videos, some files larger than 4 GB, files outside C:\Users and external or network drives need separate review.

Does Webroot backup protect live SQL or other databases?

No. Webroot says live SQL, Exchange, Access and similar databases are unsupported at file level. Use the database application to create a consistent backup file, then select that file for cloud backup.

How many previous file versions does Webroot keep?

Webroot documents up to 12 versions: daily versions for the past week, weekly versions for the prior three weeks and monthly versions for the previous two months, subject to backup availability.

What happens to backup data after the subscription expires?

Webroot support says backed-up data remains available for 30 days after expiration. Treat that as a short recovery window, not long-term archival storage, and restore or migrate before the subscription ends.

Is the Webroot password manager really LastPass?

Yes. Current Webroot support identifies the password manager as powered by LastPass and directs users to the LastPass app or account flow. It's a separate service handoff, not a vault inside the antivirus engine.

How many LastPass accounts come with Total Protection Family?

The public plan page doesn't clearly state a LastPass seat count. Don't assume it matches ten devices or ten identities; verify the entitlement shown in Webroot MyAccount before buying for a household.

Is LastPass safe after the 2022 incident?

LastPass says it rebuilt infrastructure, increased PBKDF2 iterations and added security controls. Its official incident report also confirms encrypted and unencrypted customer data was taken from cloud backups. That history deserves an informed risk decision, a strong master password, MFA and an exit plan.

Can Webroot cloud backup replace an offline backup?

No. CISA recommends offline, encrypted backups and regular restore testing because ransomware can target accessible backups. Keep another copy that isn't continuously reachable from the protected computer.

Bottom line: prove recovery before trusting the bundle

Webroot gives one PC or Mac a useful off-site backup and sends password management to LastPass. Neither feature is ready merely because Total Protection is paid for. Confirm the entitlement, inspect the files, restore one and secure the vault.

Then add the missing independence: an offline file copy, recovery material outside the vault and a safe migration path. That turns a convenient subscription into a recovery plan instead of a collection of unchecked icons.