What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bitwarden offers several controls that can improve account protection or reduce the risk of leaving an unlocked vault unattended. This is an editorial selection of six useful settings and actions—not an official Bitwarden list. The exact menus and options can vary by app, device, and organization policy.

1. Enable two-step login

Two-step login adds a second verification method when you log in to Bitwarden. In the web app, go to Settings → Security → Two-step login and choose a method. Bitwarden lists FIDO2 WebAuthn credentials, authenticator apps, and email among the options available to free individual users. Some other methods, including Duo Security and YubiKey OTP, require Premium. Check the method’s requirements before choosing it.

A FIDO2 security key is optional: an authenticator app or another supported method may suit you better. FIDO2 WebAuthn and YubiKey OTP are distinct methods, so support for one does not mean every key or configuration works with the other. See Bitwarden’s two-step login guide for the current method list and setup details.

2. Save your recovery code outside Bitwarden

When you configure a two-step login method, Bitwarden generates a recovery code. Save it somewhere secure that you can access if you lose your second factor—not only inside the vault you may need the code to recover. Bitwarden says it cannot retrieve the code for you. Its recovery-code instructions explain where to find and use it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Set a finite vault timeout

A timeout controls how long Bitwarden can remain unlocked before it locks or logs out. Choose an interval that fits the device: a shared or easily accessible device calls for a shorter period than a personal device you use constantly. The available choices vary by client, and an organization policy may limit them. Check the relevant app’s settings using Bitwarden’s timeout guide.

Avoid choosing Never just to avoid unlocking. Bitwarden warns that this option stores the encryption key unencrypted on the device, which may hinder security.

4. Choose what the timeout does: lock or log out

The timeout action determines what happens when the interval expires. The difference is a practical tradeoff between keeping local access convenient and requiring a fresh login.

Action What happens to local vault data What you need to access it again
Lock Data stays on the device. Unlock the vault; this can work offline.
Log out Local vault data is removed. Reconnect and log in again, including the active two-step method.

Neither action is the right choice for every device. Locking is more convenient, while logging out requires online reauthentication. Bitwarden describes client-specific behavior in its timeout documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Check the account’s available vault health reports

Vault health reports can help identify exposed, reused, or weak passwords. Availability depends on the account: most reports require Premium or a paid organization, while the Data Breach report is free for all users. The reports are accessed from the web app; consult Bitwarden’s reports guide for current access requirements and instructions.

There is also a privacy detail worth knowing: Bitwarden says several reports run locally. For its exposed-password process, the app uses a partial-hash lookup and compares full hashes locally. That description applies to the specified process, not necessarily every report.

6. Review devices and deauthorize sessions if a login looks unfamiliar

Deauthorizing sessions is a response to a suspected unrecognized login, not a routine setting you need to change daily. If you receive a new-device login you do not recognize, Bitwarden’s security FAQ recommends changing your master password, ensuring two-step login is enabled, and deauthorizing sessions. Follow its security FAQ for the account steps. Deauthorizing sessions can force other sessions to reauthenticate, so be prepared to sign in again on devices you use.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why is Bitwarden not asking for two-step login?

Two-step login applies when you log in; unlocking a vault in an already active local session is a separate step. After login, you may unlock with your master password, PIN, or biometrics without repeating two-step verification. Bitwarden also documents a per-device Remember me option that may skip the prompt for 30 days. The distinction between login and unlock explains why a vault can ask for a PIN or biometrics without asking for your second factor. See Bitwarden’s two-step login FAQ for details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where to find other app-specific controls

PIN and biometric unlock, device management, and other settings can also be useful, but their exact names and locations depend on the Bitwarden client and operating system. Use the relevant app’s settings rather than assuming the web app’s menu applies everywhere. Bitwarden’s help center links to client-specific guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.