Secure Account Access Securing Access Once logged in, Bitwarden uses insecure settings by default. It is strongly recommended to do the following steps Session Timeouts Setting session timeouts is essential to prevent anyone with physical access to your devices from stealing passwords Web Vault Once logged in, go to Settings -> Security -> Session timeout. Set the timeout to something you're comfortable with. Browser Extension Once logged in, got to Settings -> Account security Set the Session timeout to something you're comfortable with. Mobile App This process is very similar to "Browser Extension". Find Account security and set the Session timeout Two-factor Login (TFA) Your passwords protect you, your vault protects your passwords. Protect your vault. This step must be performed in the Web Vault at https://warden.firehawk-systems.com Once logged in, navigate to Settings -> Security -> Two-step login If you have a YubiKey and know how to use it, select Passkey. Otherwise select the "Manage" button next to Email. You will be prompted for your password again. Do not select Authenticator app unless you know what you are doing, Bitwarden app should never be used for this Enter the code that gets sent once 'Send email" is clicked. A green tick will appear next to Email when successful Save Recovery Code The recovery code is required to regain access to your account if the primary TFA method fails, and should be stored somewhere safe. In the warning box, click "View recovery code". You will be prompted for your password again. Highlight and copy the pink text, then save somewhere safe. You have completed the securing of your Bitwarden Account