Add a Trusted Device
When you become a member of an organization, the device you log in with for the first time will automatically be registered as a trusted device. Once this occurs, all you'll need to do to log in to Bitwarden and decrypt your vault data is complete your company's established single sign-on flow.
tip
Devices will be trusted by default when you log in on them. It is highly recommended that you uncheck the Remember this device option when logging in on a public or shared device.
When you log into a new device however, you'll need to approve, or trust, that device. There are a few methods for doing so:
Approve from another device: If you have another Bitwarden Password Manager mobile app or desktop app you're currently logged in to, you can approve the new device from there, as long as the Approve login requests option is enabled.
tip
We recommend trusting a mobile or desktop app first and immediately turning on the Approve login requests option. This will allow you to use the Approve from another device option to add subsequent devices.
Request admin approval: You can send a device approval request to admins and owners within your organization for approval. You must be enrolled in account recovery to request admin approval, though you may have been automatically enrolled when you joined the organization. In many cases, this will be the only option available to you (learn more).
note
If you use this option, you'll get an email informing you to continue logging in on the new device. You must take action by logging in to the new device within 12 hours, or the approval will expire.
Approve with master password: If you are an admin or owner, or joined your organization before SSO with trusted devices was implemented, and therefore still have a master password associated with your account, you can enter it to approve the device.
Once the new device becomes trusted, all you'll need to do to log in to Bitwarden and decrypt your vault data is complete your company's established single sign-on flow.
The initial client used to access Bitwarden for users who were invited with Just in Time (JIT) provisioning using login with SSO will become their first trusted device. If the initial client accessed is the Bitwarden desktop or mobile app, this device can be used to approve additional devices.
For the desktop or mobile app to become the first trusted device, the user should not use the organization invite link. Instead, open the mobile or desktop app and select the Enterprise single sign-on option to begin the JIT process.
Devices will remain trusted until:
The application or extension is uninstalled.
The web browser's memory is cleared (web app only).
The user's encryption key is rotated.
note
Only users who have a master password can rotate their account encryption key. Learn more.
Suggest changes to this page
How can we improve this page for you?
For technical, billing, and product questions, please contact support