Unable to unlock Bitwarden desktop app on app start using Windows Hello

No, unfortunately, you are not making sense to me. Experience or not, it seems that you have significantly misunderstood the current limitations on biometric unlock, and the available work-arounds.

I guess I must have misunderstood something here. My understanding was that the Windows Hello unlock implementation was secure but had issues gaining application focus, and so the feature was removed to offer a better user experience to those affected by the poor user experience.

The feature has not been removed. The main change is that if you close the Desktop app and subsequently restart it, then the first unlock after app restart must use a password (master password or alternative password configured under the “PIN” option). For all subsequent unlocks, you can use biometrics without entering any password.

Hmmmm… yeah, I must admit, I tried to imply that. – But I think, we overlooked a change here too. I just realized, on my desktop app 2025.9.0 (maybe even since 2025.8.0?), there no longer is the option to “circumvent” using the master password with PIN unlock on first unlock after app start as well:

2025-09-20--17-48-51-VDC5hHIjOb

So in fact, you are required to type in the master password on app (re)start at the moment. (at least for the desktop app)

False alarm! It’s still there, but just hidden, as @grb pointed out in the “next” post here. (and I don’t delete my post as my mistake may help others now :sweat_smile:)

PS: I didn’t want to restart the whole discussion now… please all bear in mind, that there are concrete efforts to reintroduce biometric unlock on app start:

2 Likes

The option is “hidden”, and is only seen when you first set up the PIN. To enable or disable the option when you already have a PIN, you first need to disable “Unlock with PIN”, and then re-enable that option:

1 Like

Ah, obviously I didn’t remember that it was that much “hidden”. I’ll change my previous post.

PS: And the desktop app and browser extensions are inconsistent here (the latter doesn’t hide that sub-option when “turned on”):

Since some time, the master password need to be entered in order to unlock the desktop version of Bitwarden. Unlock with Windows Hello works afterwards… but not before.

I need to do this every day. I assume something changed, but it’s very very annoying.

Bitwarden version:

@klodoma I moved your post into the relevant thread.

First, see this from the Release Notes 2025.8.0:

The latest update from Bitwarden from @Micah_Edelblut:

2 Likes

At some point, I presume after an update, Bitwarden desktop app in Windows started to require entering master password to unlock the vault after a Windows reboot despite my setting to lock the vault on timeout action. I have the timeout set to “on system lock”. In previous versions, all I needed was biometric verification to unlock the vault after a reboot. In my case, I use a fingerprint sensor or camera via Windows Hello. I wanted to ask if this change was intentional and if it was due to security concerns. Thanks.

Yes, this change was intentional, see this answer for details.

2 Likes

@mveras1972 I moved your post into the corresponding thread. See the posts above for more explanations etc.

1 Like

Thank you. I did notice that the web extension now works more predictably and consistent than before and that is a welcomed behavior.

2 Likes

Hi all, I understand that the whole re-key-in password on app restart is a thing now and I am okay with that.

I have a query on making my workflow more smooth.

On app restart, is there a way to add the mobile notification login without logging out. Right now, I have to logout to use that functionality, which is kinda weird tbh. I also don’t want to logout everytime my vault timeouts.

If not, could there be a separate option added to set “auto-logout” on app restart?

@user154 Welcome to the forum!

You could propose this as a feature request.

A work-around that may accomplish the same result would be to create a shell script that deletes the Desktop app’s data.json cache, and then use your operating system’s scheduler to trigger that script to be executed whenever the Desktop app is closed.

1 Like

There is also a related feature request that you can vote for (which was already mentioned above):

So there was a bug with a windows feature that affected SOME users, and the solution is to inconvenience every user? I can understand making it an option so that the affected users can have a better experience, but we are encouraged to make incredibly long and complex master passwords, and now you are telling my I need to keep entering it? It very much defeats the purpose.

Bring back the old functionality with a setting for the affected people. Very poorly thought out decision.

@Piercy Welcome to the forum!

A fix to restore Windows Hello unlock on app restart has already been developed (PR #16432), and should be available in an upcoming release.

The underlying issue and justifications for changes made have been discussed at length in Github Issue #16106.

Do note that if you keep the desktop app running and logged in, but locked, you only need to enter the master password upon reboot. If even that is too burdensome, you might check out login with device until another fix comes about.

Found in the 2025.11.0 release notes:

  • Windows Hello update: You can now unlock your vault with biometrics immediately after the Windows desktop app restarts, rather than entering a master password or PIN. When setting up biometrics in the Windows desktop app, uncheck Require master password or PIN on app restart.
3 Likes

Still doesn’t work on v11.0

Below is when Windows Hello option enabled. Disabled Windows Hello, re-enabled it again, there’s no checkbox that says, “Require master password or PIN on app restart.” anywhere. There’s no Windows Hello prompt when re-enabling it either. However, when vault is locked (not logged out), Windows Hello works. Biometric thru browser extension is broken.

1 Like