9 changed files with 191 additions and 229 deletions
@ -1,77 +1,91 @@
@@ -1,77 +1,91 @@
|
||||
--- |
||||
layout: article |
||||
title: Bitwarden for Enterprise - Feature List |
||||
categories: [plans-and-pricing] |
||||
title: Bitwarden for Enterprise Features Datasheet |
||||
categories: [business] |
||||
featured: false |
||||
popular: false |
||||
hidden: false |
||||
tags: [enterprise, plans, organization] |
||||
order: 04 |
||||
order: 03 |
||||
--- |
||||
|
||||
|ENTERPRISE FEATURES |DESCRIPTION| |
||||
|---------------------|----------------------| |
||||
|**Application range and ease-of-use**| | |
||||
|Wide download and deployment options | Cloud, private cloud, self-hosted, mobile, desktop, CLI <br>[https://bitwarden.com/download/](https://bitwarden.com/download/) | |
||||
|Mobile Apps (with Mobile Login Controls) | Available for iOS and Android <br> [https://bitwarden.com/help/article/getting-started-mobile/](https://bitwarden.com/help/article/getting-started-mobile/) | |
||||
|Browser extensions | Chrome, Firefox, Opera, Edge, Vivaldi, Brave, Tor, Safari <br> [https://bitwarden.com/help/article/getting-started-browserext/](https://bitwarden.com/help/article/getting-started-browserext/) | |
||||
|Desktop applications | Windows, Mac, Linux <br> [https://bitwarden.com/help/article/directory-sync-desktop/](https://bitwarden.com/help/article/directory-sync-desktop/) | |
||||
|Web Vault | Fully encrypted web application at vault.bitwarden.com | |
||||
|Streamlined UI design | | |
||||
|**Administrative features and capabilities**| | |
||||
|Admin Password Reset | Provides designated administrators the ability to reset passwords on end-user accounts if an employee loses or forgets their Bitwarden password <br> [https://bitwarden.com/help/article/admin-reset/](https://bitwarden.com/help/article/admin-reset/)| |
||||
|Directory Connector | Synchronize with your existing directory. Provision, de-provision users, groups, group associations| |
||||
|User type access controls| Custom role, granular controls (hide passwords, read only), password inheritance and custodianship, LDAP group permissions, Personal and Company Vaults | |
||||
|User management |Add/remove seats, onboard/offboard users (flags and assistance) | |
||||
|Enterprise Policies |Enables Enterprise Organizations to enforce security rules for all users, for example mandating use of Two-step Login. [https://bitwarden.com/help/article/policies/](https://bitwarden.com/help/article/policies/) | |
||||
|**Security**| | |
||||
|Secure storage for Logins, Notes, Cards, and Identities| Bitwarden Vault items | |
||||
|Secure password generator |Generate secure, random passwords <br> [https://bitwarden.com/password-generator/](https://bitwarden.com/password-generator/) | |
||||
|Encrypted export |Download encrypted exports from Bitwarden clients <br> [https://bitwarden.com/help/article/encrypted-export/](https://bitwarden.com/help/article/encrypted-export/) | |
||||
|Biometrics, mobile |Android (Google Play or FDroid); iOS (Touch ID, Face ID) <br> [https://bitwarden.com/help/article/biometrics/](https://bitwarden.com/help/article/biometrics/) | |
||||
|Biometrics, desktop | Windows (Windows Hello using PIN, Facial Recognition, or other hardware that meets Windows Hello biometric requirements); macOS (Touch ID) <br> [https://bitwarden.com/help/article/biometrics/](https://bitwarden.com/help/article/biometrics/)| |
||||
|Biometrics, browser extensions |Chromium-based browsers (Chrome, Edge, Opera, Brave, etc.), Firefox 87+, and Safari 14+ <br> [https://bitwarden.com/help/article/biometrics/](https://bitwarden.com/help/article/biometrics/)| |
||||
|Emergency Access | Users can designate and manage trusted emergency contacts <br> [https://bitwarden.com/help/article/emergency-access/](https://bitwarden.com/help/article/emergency-access/) | |
||||
|Zero knowledge encryption |All Vault data is end-to-end encrypted <br> [https://bitwarden.com/blog/post/bitwarden-network-security-assessment-2020/](https://bitwarden.com/blog/post/bitwarden-network-security-assessment-2020/) | |
||||
| Account fingerprint phrase |Uniquely and securely identifies a Bitwarden user account when encryption-related operations are performed. <br> [https://bitwarden.com/help/article/fingerprint-phrase/](https://bitwarden.com/help/article/fingerprint-phrase/)| |
||||
|Subprocessors| Full list: [https://bitwarden.com/help/article/subprocessors/](https://bitwarden.com/help/article/subprocessors/) | |
||||
|**Authentication**| | |
||||
|Two factor authentication| [https://bitwarden.com/help/article/setup-two-step-login/](https://bitwarden.com/help/article/setup-two-step-login/) | |
||||
|Login with SSO | Use your existing Identity Provider to perform authentication for Bitwarden via SAML or OPENID <br> [https://bitwarden.com/help/article/about-sso/](https://bitwarden.com/help/article/about-sso/) | |
||||
|Two-step login |Duo for Organizations <br> [https://bitwarden.com/help/article/setup-two-step-login-duo/](https://bitwarden.com/help/article/setup-two-step-login-duo/) | |
||||
|Touch ID/ Windows Hello Support |Configure Bitwarden to accept biometrics was a method to unlock your Vault <br> [https://bitwarden.com/help/article/biometrics/](https://bitwarden.com/help/article/biometrics/)| |
||||
|**Compliance, Audits, Certifications**| | |
||||
|SOC 2 Type 2 |[https://bitwarden.com/blog/post/bitwarden-achieves-soc-2-certification/](https://bitwarden.com/blog/post/bitwarden-achieves-soc-2-certification/)| |
||||
|2018 Security Assessment|[https://bitwarden.com/blog/post/third-party-security-audit/](https://bitwarden.com/blog/post/third-party-security-audit/)| |
||||
|2020 Security Assessment | [https://bitwarden.com/blog/post/bitwarden-network-security-assessment-2020/](https://bitwarden.com/blog/post/bitwarden-network-security-assessment-2020/)| |
||||
|White box testing | Performed by unit tests and QA Engineers | |
||||
|Black box testing |Performed via automation or manual testing | |
||||
|Bug bounty program |HackerOne <br> [https://hackerone.com/bitwarden/?type=team](https://hackerone.com/bitwarden/?type=team)| |
||||
|**Privacy**| | |
||||
|GDPR, CCPA, HIPAA, Privacy Shield | [https://bitwarden.com/compliance/](https://bitwarden.com/compliance/)| |
||||
|**Reporting**| | |
||||
|Vault Health reports| Exposed passwords, reused passwords, weak passwords, and more <br>[https://bitwarden.com/help/article/reports/](https://bitwarden.com/help/article/reports/)| |
||||
| Data breach reports |compromised data (email addresses, passwords, credit cards, DoB, etc.) in known breaches [https://bitwarden.com/help/article/reports/](https://bitwarden.com/help/article/reports/)| |
||||
|Event logs |User, item, collection, group, organization events <br> [https://bitwarden.com/help/article/event-logs/](https://bitwarden.com/help/article/event-logs/)| |
||||
|**Directory integration**| | |
||||
| Bitwarden Directory Connector|Sync with Active Directory or LDAP, Azure, G Suite, Okta, OneLogin <br>[https://bitwarden.com/help/article/directory-sync/](https://bitwarden.com/help/article/directory-sync/)| |
||||
|**Single Sign On (SSO)**| | |
||||
|SAML 2.0|Enabling login with SSO for SAML 2.0 <br> [https://bitwarden.com/help/article/configure-sso-saml/](https://bitwarden.com/help/article/configure-sso-saml/)| |
||||
|OIDC | Enabling login with SSO for OpenID Connect <br> [https://bitwarden.com/help/article/configure-sso-oidc/](https://bitwarden.com/help/article/configure-sso-oidc/) | |
||||
| Link existing account | Link existing account to SSO <br> [https://bitwarden.com/help/article/link-to-sso/](https://bitwarden.com/help/article/link-to-sso/) | |
||||
| Vault access| Authenticate Vault using SSO <br> [https://bitwarden.com/help/article/sso-access-your-vault/](https://bitwarden.com/help/article/sso-access-your-vault/)| |
||||
| **APIs and Extensibility** | | |
||||
|Programmatically accessible| Public and private APIs <br> [https://bitwarden.com/help/article/public-api/](https://bitwarden.com/help/article/public-api/) | |
||||
| Command line interface |Public and private APIs Fully featured CLI client application <br>[https://bitwarden.com/help/article/cli/](https://bitwarden.com/help/article/cli/)| |
||||
| Extensibility Plug-in and extension supports|Output log data via the API, automate workflows with the API and CLI| |
||||
|**Technical implementation**| | |
||||
|Passwords stored encrypted in-memory until revealed| [https://bitwarden.com/help/article/security-faqs/](https://bitwarden.com/help/article/security-faqs/) | |
||||
|Strong and flexible password generation| Configurable password generator. Policy for Password Generator strength <br>[https://bitwarden.com/password-generator/](https://bitwarden.com/password-generator/) |
||||
| Vendor cannot access passwords |Bitwarden employs a zero-knowledge encryption model with no ability to see customer vault data | |
||||
|Confirming to cryptography standards |[https://bitwarden.com/help/article/what-encryption-is-used/](https://bitwarden.com/help/article/what-encryption-is-used/) | |
||||
| **Resiliency** | | |
||||
|Local cache/offline access|[https://bitwarden.com/help/article/sso-faqs/](https://bitwarden.com/help/article/sso-faqs/) | |
||||
|**Extras**| | |
||||
|Temporary password sharing and generation| [https://bitwarden.com/help/article/authenticator-keys/](https://bitwarden.com/help/article/authenticator-keys/) | |
||||
|Auto clear clipboard after copying a password| [https://bitwarden.com/help/article/security-faqs/](https://bitwarden.com/help/article/security-faqs/) | |
||||
|Duplicate password detection| [https://bitwarden.com/help/article/reports/](https://bitwarden.com/help/article/reports/)| |
||||
This document describes and references the features available to Bitwarden Enterprise Organizations in several categories: |
||||
|
||||
#### Application Range and Ease-of-use |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|Deployment Options|Cloud, Private Cloud, and Self-hosted.| |
||||
|Web Application|Fully encrypted cloud web app at [https://vault.bitwarden.com](https://vault.bitwarden.com){:target="\_blank"}, or on your self-hosted server| |
||||
|Mobile Apps (with Mobile Login Controls)|Available for iOS and Android. [Learn more]({{site.baseurl}}/article/getting-started-mobile/).| |
||||
|Browser Extensions|Available for Chrome, Firefox, Opera, Edge, Vivaldi, Brave, Tor, and Safari. [Learn more]({{site.baseurl}}/article/getting-started-browserext/).| |
||||
|Desktop Applications|Available for Windows, Mac, and Linux. [Learn more]({{site.baseurl}}/article/directory-sync-desktop/).| |
||||
|CLI|Fully featured and self-documented command-line tool. [Learn more]({{site.baseurl}}/article/cli/). |
||||
|Streamlined UI Design|Simple and uniform interfaces across apps for complete ease-of-use.| |
||||
|
||||
#### Administrative Features and Capabilities |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|Simple User Management|Add or remove seats and onboard or offboard users directly from the Web Vault. [Learn more]({{site.baseurl}}/article/managing-users/).| |
||||
|Role Based Access Control|Assign role-based access for Organization users, including a custom role and granular permissions (e.g. Hide Passwords, Read-Only). [Learn more]({{site.baseurl}}/article/user-types-access-control/).| |
||||
|Directory Sync|Synchronize your Bitwarden Organization with your existing user directory. Provision and de-provision users, groups, and group associations. [Learn more]({{site.baseurl}}/article/directory-sync/).| |
||||
|Admin Password Reset |Designated administrators can reset Master Password of end-user accounts if an employee loses or forgets their Master Password. [Learn more]({{site.baseurl}}/article/admin-reset/).| |
||||
|Enterprise Policies|Enforce security rules for all users, for example mandating use of Two-step Login. [Learn more]({{site.baseurl}}/article/policies/).| |
||||
|Temporary Password Sharing and Generation| Create and share ephemeral data using Bitwarden Send. [Learn more]({{site.baseurl}}/article/about-send/).| |
||||
|
||||
#### Reporting |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|Vault Health Reports|Run reports for Exposed Passwords, Reused Passwords, Weak Passwords, and more. [Learn more]({{site.baseurl}}/article/reports/).| |
||||
|Data Breach Reports|Run reports for data compromised in knwon breaches (e.g. Email Addresses, Passwords, Credit Cards, DoB, etc.). [Learn more]({{site.baseurl}}/article/reports/).| |
||||
|Event Logs|Get timestamped records of events that occur within your Organization Vault for easy use in the Web Vault or ingestion by other systems. [Learn more]({{site.baseurl}}/article/event-logs/).| |
||||
|
||||
#### Authentication |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|2FA for Individuals|A robust set of 2FA options for any Bitwarden user. [Learn more]({{site.baseurl}}/article/setup-two-step-login/).| |
||||
|2FA at Organization-level|Enable 2FA via Duo for your entire Organization. [Learn more]({{site.baseurl}}/article/setup-two-step-login-duo/).| |
||||
|Biometric Authentication|Available for:<br>-Android (fingerprint unlock or face unlock) and iOS (Touch ID and Face ID)<br>-Windows Desktop Apps (Windows Hello using PIN, Facial Recognition, and more) and macOS Desktop Apps (Touch ID)<br>-Chromium, Firefox 87+, and Safari Browser Extensions<br><br>[Learn more]({{site.baseurl}}/article/biometrics/).| |
||||
|Login with SSO|Leverage your existing Identity Provider to authenticate your Bitwarden Organization users via SAML 2.0 or OpenID Connect (OIDC). [Learn more]({{site.baseurl}}/article/about-sso/).| |
||||
|
||||
#### Security |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|Secure storage for Logins, Notes, Cards, and Identities|Bitwarden [Vault items]({{site.baseurl}}/article/managing-items/) are encrypted before being stored anywhere. [Learn more]({{site.baseurl}}/article/what-encryption-is-used/).| |
||||
|Zero Knowledge Encryption |All Vault data is end-to-end encrypted. [Learn more](https://bitwarden.com/blog/post/bitwarden-network-security-assessment-2020/).| |
||||
|Secure Password Generator|Generate secure, random, and unique passwords for every Vault item. [Learn more](https://bitwarden.com/password-generator/).| |
||||
|Encrypted Export|Download encrypted exports for secure storage of Vault data backups. [Learn more]({{site.baseurl}}/article/encrypted-exports/).| |
||||
|Biometric Authentication|Available for:<br>-Android (fingerprint unlock or face unlock) and iOS (Touch ID and Face ID)<br>-Windows Desktop Apps (Windows Hello using PIN, Facial Recognition, and more) and macOS Desktop Apps (Touch ID)<br>-Chromium, Firefox 87+, and Safari Browser Extensions<br><br>[Learn more]({{site.baseurl}}/article/biometrics/).| |
||||
|Emergency Access|Users can designate and manage trusted emergency contacts, who may request access to their Vault in case of emergency. [Learn more]({{site.baseurl}}/article/emergency-access/).| |
||||
|Account Fingerprint Phrase|Security measure that uniquely and securely identifies a Bitwarden user account when encryption-related or onboarding operations are performed. [Learn more]({{site.baseurl}}/article/fingerprint-phrase/).| |
||||
|Subprocessors|See our full list of subprocessors: [Bitwarden Subprocessors](https://bitwarden.com/help/article/subprocessors/).| |
||||
|
||||
#### Compliance, Audits, Certifications |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|SOC 2 Type 2 |[Read about our SOC 2 Type 2 Certification](https://bitwarden.com/blog/post/bitwarden-achieves-soc-2-certification/).| |
||||
|2018 Security Assessment|[Read our 2018 Security Assessment](https://bitwarden.com/blog/post/third-party-security-audit/).| |
||||
|2020 Security Assessment|[Read our 2020 Security Assessment](https://bitwarden.com/blog/post/bitwarden-network-security-assessment-2020/).| |
||||
|GDPR, CCPA, HIPAA, & Privacy Shield|[Read about our compliance with various privacy frameworks](https://bitwarden.com/compliance/).| |
||||
|White-box Testing |Performed by unit tests and QA Engineers.| |
||||
|Black-box Testing |Performed via automation and manual testing.| |
||||
|Bug Bounty Program|Conducted through HackerOne. [Learn more](https://hackerone.com/bitwarden/?type=team).| |
||||
|
||||
#### APIs and Extensibility |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|Programmatically Accessible|Public and Private APIs for Organizations. [Learn more]({{site.baseurl}}/article/public-api/).| |
||||
|Command Line Interface|Fully featured and self-documented command-line tool. [Learn more]({{site.baseurl}}/article/cli/)| |
||||
|Extensibility Support|Automate workflows by combining API and CLI.| |
||||
|
||||
#### Resiliciency |
||||
|
||||
|Enterprise Features|Description| |
||||
|-------------------|-----------| |
||||
|Local Cache & Offline Access|[Learn more]({{site.baseurl}}/article/security-faqs/).| |
||||
|
||||
@ -0,0 +1,5 @@
@@ -0,0 +1,5 @@
|
||||
--- |
||||
layout: category |
||||
title: Business Resources |
||||
featured: true |
||||
--- |
||||
Loading…
Reference in new issue