Browse Source
* Remove references to "Zero Trust" and downcase non-header instances of "zero knowledge" * Morph "Link SSO" and "Access Vault using SSO" articles into a single "Using Login with SSO" one-stop-shop guide for end-users (i.e. non-configuration) + redirects + updated hyperlinks * Update _articles/getting-started/getting-started-organizations.md Co-authored-by: Trey Greer <61418192+tgreer-bw@users.noreply.github.com> Co-authored-by: Trey Greer <61418192+tgreer-bw@users.noreply.github.com>pull/740/head
12 changed files with 63 additions and 90 deletions
@ -1,24 +0,0 @@
@@ -1,24 +0,0 @@
|
||||
--- |
||||
layout: article |
||||
title: Link an Existing Account to SSO |
||||
categories: [login-with-sso] |
||||
featured: false |
||||
popular: false |
||||
tags: [] |
||||
order: 05 |
||||
--- |
||||
|
||||
Users with existing Bitwarden accounts will need to complete the following steps when their Organization applies Login with SSO: |
||||
|
||||
1. In the Web Vault, navigate to your **Settings** tab and open your **Organizations**. |
||||
2. Hover over the desired Organization and select the gear dropdown. |
||||
|
||||
{%image /sso/sso-link-button-overlay.png Link SSO Dropdown Option %} |
||||
|
||||
3. From the dropdown menu, select **Link SSO**. |
||||
|
||||
Selecting this option will initiate an authentication session to link your account. Successfully linking your account to SSO will allow you to use Login with SSO to authenticate into your Vault. |
||||
|
||||
### Next Steps |
||||
Now that you've linked your account, you can now: |
||||
- [Access your Vault Using SSO](https://bitwarden.com/help/article/sso-access-your-vault/) |
||||
@ -1,43 +0,0 @@
@@ -1,43 +0,0 @@
|
||||
--- |
||||
layout: article |
||||
title: Access Your Vault Using SSO |
||||
categories: [login-with-sso] |
||||
featured: false |
||||
popular: false |
||||
tags: [sso] |
||||
order: 06 |
||||
--- |
||||
|
||||
## Before You Begin |
||||
If you are an existing Bitwarden user, you must [Link an Existing Account to SSO](https://bitwarden.com/help/article/link-to-sso/) before authenticating into your Vault using Login with SSO. |
||||
|
||||
## Logging in with SSO |
||||
|
||||
Complete the following steps to use Login with SSO to authenticate into your Bitwarden Vault: |
||||
|
||||
1. Open your Bitwarden App or navigate to the Bitwarden Web Vault. |
||||
2. Select the **Enterprise Single Sign-On** button. |
||||
|
||||
{% image sso/sso-button-lg.png Enterprise Single Sign-On button %} |
||||
|
||||
3. Enter your **Organization Identifier** and select **Log In**. |
||||
|
||||
{% callout info %}We recommend bookmarking this page with your Organization Identifier included as a query string so that you don't have to enter it each time, for example `https://vault.bitwarden.com/#/sso?identifier=your-org-id` or `https://your.domain.com/#/sso?identifier=your-org-id`. |
||||
{% endcallout %} |
||||
|
||||
{% image sso/org-id-input.png Organization Identifier field %} |
||||
|
||||
A browser window will open prompting you to enter your SSO credentials or other required authentication mechanisms. |
||||
|
||||
Upon successful authentication: |
||||
|
||||
- **For existing accounts**, you will be re-directed to the Bitwarden login page and prompted to enter your Master Password to decrypt your Vault data. |
||||
- **For new accounts**, you will be prompted to create a Master Password and (optionally) provide a hint. Users with new accounts will need to have access confirmed for shared Organization items, including Collections and Groups. |
||||
|
||||
In both cases, your account now has an *accepted* status within your Organization. |
||||
|
||||
|
||||
|
||||
{% callout info %} |
||||
Users that are created via Login with SSO **will still be properly organized into their groups and collections** if leveraging the [Directory Connector](https://bitwarden.com/help/article/directory-sync/) utility. |
||||
{% endcallout %} |
||||
@ -0,0 +1,52 @@
@@ -0,0 +1,52 @@
|
||||
--- |
||||
layout: article |
||||
title: Using Login with SSO |
||||
categories: [login-with-sso] |
||||
featured: false |
||||
popular: false |
||||
tags: [sso] |
||||
order: 04 |
||||
redirect_from: |
||||
- /article/link-to-sso/ |
||||
- /article/sso-access-your-vault/ |
||||
--- |
||||
|
||||
As an end-user of Bitwarden, you will need to [link your account to SSO](#link-your-account-to-sso) and get your [Organization identifier](#get-your-organization-identifier) before you can [login using SSO](#login-using-sso): |
||||
|
||||
## Link your Account |
||||
|
||||
To link your account: |
||||
|
||||
1. Open the Web Vault, navigate to your **Settings** tab and open your **Organizations**. |
||||
2. Hover over the desired Organization and select the {% icon fa-cog %} gear dropdown: |
||||
|
||||
{%image /sso/sso-link-button-overlay.png Link SSO Dropdown Option %} |
||||
|
||||
3. From the dropdown menu, select {% icon fa-link %} **Link SSO**. |
||||
|
||||
## Get your Organization Identifier |
||||
|
||||
Every Bitwarden Organization has a unique identifier specifically for Login with SSO. You'll need this value to login, so ask your manager or Bitwarden administrator to [retrieve it for you]({{site.baseurl}}/article/configure-sso-saml/#step-1-set-an-organization-identifier). |
||||
|
||||
## Login using SSO |
||||
|
||||
To login to Bitwarden using SSO: |
||||
|
||||
1. Open your Bitwarden Web Vault or App and select the **Enterprise Single Sign-On** button: |
||||
|
||||
{% image sso/sso-button-lg.png Enterprise Single Sign-On button %} |
||||
|
||||
2. Enter your **Organization Identifier** and select **Log In**: |
||||
|
||||
{% image sso/org-id-input.png Organization Identifier field %} |
||||
|
||||
{% callout success %}We recommend bookmarking this page with your Organization Identifier included as a query string so that you don't have to enter it each time, for example `https://vault.bitwarden.com/#/sso?identifier=YOUR-ORG-ID` or `https://your.domain.com/#/sso?identifier=YOUR-ORG-ID`.{% endcallout %} |
||||
3. Now that you've authenticated your identity using Login with SSO, enter your [Master Password]({{site.baseurl}}/article/master-password/) on the Login screen to **decrypt** your Vault. |
||||
|
||||
{% callout success %} |
||||
**Why is my Master Password still required?** |
||||
|
||||
All Vault data, including credentials [shared by your Organization]({{site.baseurl}}/article/sharing), is kept by Bitwarden **only** in its encrypted form. This means that in order to use any of those credentials, **you** need a way to decrypt that data (we can't). |
||||
|
||||
Your Master Password is the source of that decryption key. Even though you're authenticating (proving your identity) to Bitwarden using SSO, you still must use that decryption key (your Master Password) to see any meaningful data. |
||||
{% endcallout %} |
||||
|
Before Width: | Height: | Size: 53 KiB After Width: | Height: | Size: 44 KiB |
Loading…
Reference in new issue