Control over Claimed Domains overriding base domain option

I am not sure why I have never noticed this before or if something has changed, but when I go to login to a Microsoft site, I am seeing all the logins I have for what I can only assume is every Microsoft claimed domain.

While this is handy in some situations, I have a lot of logins for all sorts of accounts that are for specific Microsoft properties, and seeing all of them appear when I go to autofill for say MS365, is disconcerting.

Is there a way to force the base host and ignore the claimed domains? I would much rather set these myself manually. Then I can keep personal and various other cloud services separate.

The only way around it I can see is to set all the accounts as Host matching and then put in the additional domains each one needs.

Cheers

Mark

If you don’t make any configuration changes under Settings > Autofill, then Bitwarden’s URI match detection will default to Base Domain matching. Therefore, every website that has a login page on a domain ending with microsoftonline.com will match every vault item that contains a microsoftonline.com URI (and every matching vault item will be listed in Bitwarden’s autofill suggestions).

I don’t know exactly what you mean by “Microsoft claimed domain”, but if you provide additional detail about your use-case, I may be able to offer further assistance.

Maybe I misunderstand things, but I think there is a feature in BW that lets a domain owner claim their domains so they get treated as the same domain. So for microsoft even if I have a password set as based domain for microsoft dot com it will match live and cloud dot microsoft and all the old azure domains, etc.

I don’t remember seeing it do this before, but I also can’t remember if I have had lunch today so that’s not useful data.

So when I go to autofill and I have base domain set, I see all the Microsoft related domains on a Microsoft site.

Just read instead of skim reading the claimed domains thing… that’s not what that does, so F for me on that one.

But I still am getting all microsoft domains somehow being treated as the same base domain (except cloud dot microsoft it sees).

Is there a setting I have changed that I cannot find?

And I found it.. it’s just not accessible from the extension. I should have checked sorry. It’s Equivalent Domains.

I will customise from there… sorry for not working this out, I did search but got bamboozled by my ADHD :slight_smile:

Yes, reading your follow-up comments, it seems that you what you were looking for is the Domain Rules, which are configurable in the Web Vault. Do note that these “equivalent domains” only work when your match detection methods is specified as Base Domain.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.