User-level password health reports for Organizations

As a manager of an organization I want to make sure that everyone is using my companies policies.
When I log in to the web interface as an owner or a manager I want to see who is having weak passwords in my organization so I can address it to the user. These ‘weak passwords’ should be based on my Password generator requirements.

Is this what you are looking for? Scroll down and take a look

Paid organization plans can also access these reports to analyze the items contained in the organizational vault:

  1. Log in to the web vault at https://vault.bitwarden.com.
  2. Click Settings in the top navigation bar.
  3. Click Organizations in the top navigation bar.
  4. Locate your Organization and click on it.
  5. Click Tools in the Organization’s navigation bar.
  6. Locate the Reports section.
  7. Select the report needed.

No I only get to see organization passwords.
Passwords that are added by a user (personal) can’t be managed.

I think only the passwords in a collection or organization can be monitored. Personal logins may only be viewable to the that user only.

If you wait for sometime, @tgreer or someone else will be able to answer your queries.
I don’t use Organizations

@guusberg you’re correct, as an Organization, you can only run reports on Org items. Perhaps the title of this thread should be “User-level password health reports for Organizations” or something to that effect.

I can change it, or if you would like to, or have a better title, please feel free to do so :slight_smile:

The title has been changed. Thanks for the feedback.
But what about the feature request @tgreer

This topic and votes will serve as the feature request and help us with prioritization :slight_smile:

Though the only item that may be different here is what qualifies as ‘weak’ - we’d use our standard strength calculator ZXCVBN - but could possibly reference the password’s 0-4 score as a reference for ‘acceptable’ levels of complexity. :+1:

this one…

This would be a great feature. We as organization owners/admins don’t need to see the actual password the user uses, we just need to know the strength. I can almost guarantee some users don’t use the password generator for whatever reason.

However, because of the nature of Bitwarden organizations, I think this option should only be usable where the policy for “Single Organization” is enabled since that effectively means it’s a company account.

I was about to create this topic but saw you already did, you have my full support. I am an administrator for our business account, I am also responsible for security and compliance enforcement. I had this same concern and contacted Bitwarden.

This was Bitwarden’s Support teams response: Due to our privacy policy, a user’s personal vault is not accessible by admins or owners of an organization. This includes the reports for their vaults. The user would need to run those reports themself.

This isn’t their personal account, it’s the business account that our company is paying for. We need and should to be able to enforce password standards without seeing any specific credentials.

Something as simple as below would work:

User: User 1
Exposed passwords: 10
Weak passwords: 5
Reused passwords:
Last login: 1/2023

Companies need to be able to monitor for non-compliance. The reason we need strong policies are because humans (employees) take shortcuts. Asking employees to monitor themselves without being able to confirm of is not effective.

An additional concern is when viewing event logs, it appears we can only see log events on an organizational level, not an individual level. This is another example of security administrators not being able to enforce proper compliance with users regarding security policies in place.

As a vendor who understands the needs of digital security, compliance and protecting their client’s businesses, Bitwarden should have had these basic report options baked in from the start.

Hi @justrob Welcome to the Bitwarden community and thank you for sharing this feedback. Organization Dashboards are on the Bitwarden roadmap and we expect to have more in this area next year. Bitwarden Roadmap - Feature Requests - Bitwarden Community Forums

@guusberg We are looking for administrators of teams or enterprise organizations to identify ways to improve security insights. Please fill out this screener survey if you are interested in the topic. We appreciate your time!