Skip to main content

Secure Account Access

Securing Access

Once logged in, Bitwarden uses insecure settings by default. It is strongly recommended to do the following steps

Session Timeouts

Setting session timeouts is essential to prevent anyone with physical access to your devices from stealing passwords

Web Vault

Once logged in, go to Settings -> Security -> Session timeout. Set the timeout to something you're comfortable with.

image.png

Browser Extension

Once logged in, got to Settings -> Account security

image.png

Set the Session timeout to something you're comfortable with.

image.png

Mobile App

This process is very similar to "Browser Extension". Find Account security and set the Session timeout

Two-factor Login (TFA)

Your passwords protect you, your vault protects your passwords. Protect your vault.

This step must be performed in the Web Vault at https://warden.firehawk-systems.com

Once logged in, navigate to Settings -> Security -> Two-step login

image.png

If you have a YubiKey and know how to use it, select Passkey. Otherwise select the "Manage" button next to Email. You will be prompted for your password again.

Do not select Authenticator app unless you know what you are doing, Bitwarden app should never be used for this

image.png

Enter the code that gets sent once 'Send email" is clicked. A green tick will appear next to Email when successful

Save Recovery Code

The recovery code is required to regain access to your account if the primary TFA method fails, and should be stored somewhere safe.

In the warning box, click "View recovery code". You will be prompted for your password again.

image.png

Highlight and copy the pink text, then save somewhere safe.

image.png

You have completed the securing of your Bitwarden Account