GreenLoop IT Solutions : Articles

BitWarden Best Practice – Deleting a Bitwarden Account After an Employee Exit

Introduction

In the fast-changing world of cybersecurity, keeping sensitive data safe is more important than ever. When an employee leaves, it’s crucial to keep your data confidential and intact. It’s a basic and important step to take away all access and credentials from the departing employee to avoid unauthorized access to your organization’s information. GreenLoop plays a vital role in this process with most of our partners.

GreenLoop’s Approach

GreenLoop is steadfast in ensuring the integrity of the data within our client’s organizations. We have opted for BitWarden as a password management tool, a platform known for its decentralization and robust security, ensuring that data is protected from accidental exposure. This decentralization means we, at GreenLoop, do not have direct access to manage or delete your BitWarden accounts, aligning with our commitment to safeguard sensitive information and passwords from any potential exposure.

 

Deleting a BitWarden Account:

Despite BitWarden’s robust security, situations may arise where you hold the email linked to a former employee’s BitWarden account and wish to erase that account. This step complements existing best practices, like removing ex-employees from the organization, which already blocks their access to shared credentials. The main aim is to ensure no credentials, including personal saves during their tenure, remain accessible to them. Below is a guide for the recovery and deletion of such accounts. While with tight security measures this step may appear excessive, every effort made to shrink potential attack areas amplifies the security framework.

 

Regaining and Deleting a BitWarden Account After an Employee Exit

  1. Getting Started
    • Go to the BitWarden Login Page:
      • Navigate to the BitWarden login page (BitWarden Login)
      • Initiate a Password Reset
        • Click on the “Forgot Password” link.
        • Enter the email address associated with the BitWarden account and submit the form.
        • BitWarden will send a password reset email to the provided email address.  Please reach out to GreenLoop if you need to gain access to this account, or if the account has been deleted and we can assist with this step.
  2. Access the Email Account:
    • Open the Password Reset Email
      • Log into the email account associated with the BitWarden account.
      • Locate the password reset email sent by BitWarden.
  3. Reset the Password:
    • Click on the link in the email to reset the BitWarden account password.
    • Follow the prompts to create a new password for the BitWarden account.
  4. Log Into the BitWarden Account
    • Return to the BitWarden login page and log in using the email address and the new password you have just set.
  5. Delete the BitWarden Account
    • After logging in, click on the user’s name in the top right corner of the vault.
    • Select “Settings” from the dropdown menu.
    • Click on the “My Account” tab on the left sidebar.
    • Scroll down to the “Danger Zone” at the bottom of the page.
    • Click on the “Delete Account” button.
    • A popup window will appear confirming that you want to delete the account. Fill in the necessary information and click “Delete” to proceed.
  6. Confirm the Account Deletion
    • BitWarden will send a confirmation email for the account deletion.  While you still have access to the email account, you can verify this was successful by waiting until you receive this email to disable the account again.

Conclusion:

Regaining access and subsequently deleting a BitWarden account further limits access to sensitive information an employee may have retained during their tenure. By following the above steps, you can effectively recover and delete the BitWarden account, mitigating any potential risk associated with such departures. Remember, however, that once this account has been deleted, it is not recoverable.