Equal Aqua · IT Operations

Set up Bitwarden (our Vaultwarden vault)

Equal Aqua runs its own password vault on Vaultwarden, a self-hosted, fully compatible server for the standard Bitwarden apps. You use the normal Bitwarden apps — browser extension, desktop, or mobile — you just point them at our server first. Setup follows the same shape everywhere: install, set the server address, then sign in with Enterprise single sign-on through Microsoft Entra.

Self-hosted URL
https://vaultwarden.equalaqua.org:8443/

Set this in the app's Settings screen — the one with a gear icon, shown before you ever log in — under “Self-hosted environment”. Port 8443 is part of the address, so include it. Then on the login screen, enter your email and choose Enterprise single sign-on (not “Log in with master password”) and continue with your Equal Aqua Microsoft account.

That screen will also ask for an “organization identifier” — on our server this doesn't need to match anything specific, so type anything (e.g. equalaqua) and continue; Vaultwarden always sends you to our one Microsoft Entra sign-in either way.

  1. 1

    Install the Bitwarden extension

    From the Bitwarden download page, get the extension for your browser (Chrome, Firefox, Edge, and others are all supported).

    ▶ Bitwarden downloads
  2. 2

    Point it at our server

    Click the extension icon, then the gear/settings icon on the login screen. Toggle on Self-hosted environment and paste in https://vaultwarden.equalaqua.org:8443/ as the server URL.

  3. 3

    Enter your email

    Back on the login screen, type your Equal Aqua email address and continue.

  4. 4

    Sign in with SSO

    Choose Enterprise single sign-on below the master password field, type anything for the organization identifier (it isn't checked — see the note above), and sign in with your Equal Aqua Microsoft account (approve the MFA prompt if you get one).

  5. 5

    Set your vault password

    First time in, Bitwarden asks you to create a master/vault password. This is separate from your Microsoft password — it's what encrypts your vault locally, so pick something strong and memorable.

    There's no reset link for this one: if you forget it, an admin can only reset your account, not recover the vault's contents. Consider a passphrase you'll actually remember.

  1. 1

    Install the desktop app

    Get the Windows installer from the Bitwarden download page and run it.

    ▶ Bitwarden downloads
  2. 2

    Point it at our server

    On the login screen, click the gear/settings icon. Toggle on Self-hosted environment and paste in https://vaultwarden.equalaqua.org:8443/ as the server URL.

  3. 3

    Enter your email

    Type your Equal Aqua email address and continue.

  4. 4

    Sign in with SSO

    Choose Enterprise single sign-on, type anything for the organization identifier (it isn't checked — see the note above), and sign in with your Equal Aqua Microsoft account.

  5. 5

    Set your vault password

    First time in, create a master/vault password — separate from your Microsoft password, used to encrypt your vault locally.

  1. 1

    Install the desktop app

    Get the macOS installer from the Bitwarden download page and run it.

    ▶ Bitwarden downloads
  2. 2

    Point it at our server

    On the login screen, click the gear/settings icon. Toggle on Self-hosted environment and paste in https://vaultwarden.equalaqua.org:8443/ as the server URL.

  3. 3

    Enter your email

    Type your Equal Aqua email address and continue.

  4. 4

    Sign in with SSO

    Choose Enterprise single sign-on, type anything for the organization identifier (it isn't checked — see the note above), and sign in with your Equal Aqua Microsoft account.

  5. 5

    Set your vault password

    First time in, create a master/vault password — separate from your Microsoft password, used to encrypt your vault locally.

  1. 1

    Install the desktop app

    Use the AppImage, .deb, or .rpm for your distribution from the Bitwarden download page.

    ▶ Bitwarden downloads
  2. 2

    Point it at our server

    On the login screen, click the gear/settings icon. Toggle on Self-hosted environment and paste in https://vaultwarden.equalaqua.org:8443/ as the server URL.

  3. 3

    Enter your email

    Type your Equal Aqua email address and continue.

  4. 4

    Sign in with SSO

    Choose Enterprise single sign-on, type anything for the organization identifier (it isn't checked — see the note above), and sign in with your Equal Aqua Microsoft account.

  5. 5

    Set your vault password

    First time in, create a master/vault password — separate from your Microsoft password, used to encrypt your vault locally.

  1. 1

    Install the app

    Get Bitwarden from the App Store.

    ▶ Bitwarden downloads
  2. 2

    Point it at our server

    On the welcome screen, tap the gear/settings icon (usually top-right). Toggle on Self-hosted environment and paste in https://vaultwarden.equalaqua.org:8443/ as the server URL.

  3. 3

    Enter your email

    Type your Equal Aqua email address and continue.

  4. 4

    Sign in with SSO

    Tap Enterprise single sign-on, type anything for the organization identifier (it isn't checked — see the note above), and sign in with your Equal Aqua Microsoft account (approve the MFA prompt if you get one).

  5. 5

    Set your vault password

    First time in, create a master/vault password — separate from your Microsoft password, used to encrypt your vault locally.

    Screenshots for this tab are on the way — the layout is nearly identical to Android below.

  1. 1

    Install the app

    Get Bitwarden from the Play Store.

    ▶ Bitwarden downloads
  2. 2

    Point it at our server

    On the welcome screen, tap the gear/settings icon (usually top-right). Toggle on Self-hosted environment and paste in https://vaultwarden.equalaqua.org:8443/ as the server URL.

  3. 3

    Enter your email

    Type your Equal Aqua email address and continue.

  4. 4

    Sign in with SSO

    Tap Enterprise single sign-on, type anything for the organization identifier (it isn't checked — see the note above), and sign in with your Equal Aqua Microsoft account (approve the MFA prompt if you get one).

  5. 5

    Set your vault password

    First time in, create a master/vault password — separate from your Microsoft password, used to encrypt your vault locally.

    Screenshots for this tab are on the way.

How to tell it worked

Your vault opens and shows any items already shared with you. The bottom of the login screen also shows the server address you're pointed at — double-check it reads our Vaultwarden URL, not the default Bitwarden cloud.

Need a hand?

Stuck on any step, or unsure which account to use? Reach out to your IT administrator with a screenshot of where you're stuck.