A password manager lets you use a different password for every account without memorizing every one. The security benefit comes from that separation: one reused password should not unlock several unrelated services. The manager also makes it practical to generate long, random credentials and to turn on multi-factor authentication (MFA) where an account supports it.
This guide is a setup workflow, not a ranking. Product screens and plan limits vary, so use the provider’s current instructions for the app you choose. NIST’s current Digital Identity Guidelines explicitly recognize using a password manager to select secure passwords and maintain distinct passwords for each service. CISA likewise recommends long, random, unique passwords and a password manager in its password-manager guidance.
1. Choose a manager that fits your devices and recovery needs
Before creating a vault, make a short compatibility list:
- desktop operating system and browser;
- phone or tablet operating systems;
- whether you need family or work sharing;
- whether a local/offline vault or hosted sync is the better fit; and
- which recovery and export options you are willing to maintain.
Check that the provider offers an official app or extension for every device you use. Download it from the provider’s site or the official app store, not from a sponsored search result or a third-party download mirror. Do not choose based only on a “best” label or a stale price comparison; verify the current free-tier limits, plan terms, and supported platforms.
2. Create the account and master passphrase
The master password protects the vault, so make it long, unique, and difficult to guess. A memorable passphrase made from unrelated words is usually easier to manage than a short password with predictable substitutions. CISA’s guidance describes long, random, unique passwords; NIST’s SP 800-63B guidance also supports using a password manager to create distinct credentials.
Never reuse the master password, put it in another online account, or base it on public personal information. Do not email it to yourself. If you write a recovery copy, keep it offline in a place where the people you trust can find it but visitors and ordinary malware cannot.
Treat “zero knowledge” as a recovery trade-off, not a magic safety word. A provider that cannot see your master password may not be able to reset it. Bitwarden’s current FAQ is a clear example: it says the service cannot retrieve or reset a lost master password. Set up the provider’s supported recovery method before you need it.
3. Turn on MFA for the manager itself
The password manager is a high-value account. Enable MFA immediately after the first login. Prefer a passkey or hardware security key when the provider supports it; an authenticator app is another strong option. Save the recovery codes offline and test that you can locate them without opening the vault.
Do not store the only copy of your MFA recovery code inside the vault that the code is meant to help you recover. For a family or business vault, decide who can administer access and how a departing member is removed.
4. Install the browser extension and mobile app
Install only the official extension for your browser. Extensions that autofill need permission to interact with pages and login forms; review the publisher, permissions, and update history before accepting. Keep the browser and operating system current.
On mobile, install the official app and enable autofill only after confirming that the app name and publisher are correct. Biometric unlock can make daily access convenient, but it does not replace the master password or MFA. If the phone is lost, use the provider’s device/session management to revoke access.
5. Import existing credentials carefully
You can add accounts manually, or export saved credentials from a browser or another manager and import them. The export file is often plaintext or otherwise easy to read, so treat it as a temporary secret.
The safest workflow is:
- Create the new vault and confirm that it syncs on your primary device.
- Export only the accounts you intend to migrate.
- Import the file using the provider’s documented format.
- Check a sample of logins, folders, notes, passkeys, and shared items.
- Resolve duplicates before changing passwords.
- Delete the export from the computer, recycle bin, cloud sync folder, and any temporary copy.
Bitwarden’s import instructions specifically warn that imports can create duplicates and instruct users to delete the exported data file after a successful import. Its direct browser-import feature can avoid leaving a plaintext CSV on disk for supported browsers, but follow the current instructions for the manager you selected.
6. Replace the most important passwords first
Do not try to fix every account in one sitting. Start with the accounts that can reset other accounts or expose money and identity:
- primary email and recovery email;
- banking, payment, and tax accounts;
- phone carrier and cloud storage;
- work or business administration;
- social accounts with payment or advertising access; and
- the password manager itself.
Open each account from its official site, generate a new password in the manager, save it, and sign out and back in once to confirm autofill works. Turn on MFA for the account before moving to the next one. Never use a password-manager entry to approve a suspicious login prompt; phishing can still trick you into giving away a valid credential.
7. Configure autofill deliberately
Autofill is helpful, but it should not fill credentials into an unexpected domain. Check the website address before accepting a suggestion. Keep separate entries for lookalike domains, and do not disable the browser’s security warnings just to make autofill work.
If both the browser and the new manager offer to save passwords, choose one system. Two competing stores create uncertainty about which copy is current. After confirming your migration, disable the browser’s save-password prompt or leave it off for sensitive accounts.
8. Run the security check and plan maintenance
Use the manager’s health or security report if it offers one, but understand what it measures. A report may find reused, weak, or breached passwords; it cannot prove that an account’s recovery email, device, or active sessions are safe.
Prioritize warnings for email, financial, work, and administrator accounts. Review the vault after a breach notification, a lost device, a suspicious login, or a change in who shares a family or work vault. Keep the app, browser extension, and operating system updated.
9. Make a recovery and backup plan
Decide what happens if you lose your phone, forget the master password, or the provider is unavailable. Record the provider’s recovery process, keep MFA recovery codes offline, and learn how to make an encrypted vault export. Bitwarden’s export guidance explains that unencrypted exports should not be sent over insecure channels and should be deleted immediately after use; other providers have comparable instructions.
Do not make a plaintext export your only backup. If you keep an encrypted export, document the separate key or passphrase needed to open it and test restoring a non-critical copy. A backup that has never been restored is an assumption, not a recovery plan.
Common mistakes to avoid
- Using the same master password anywhere else.
- Leaving a browser CSV export on the desktop or in cloud storage.
- Assuming a free plan includes every sharing, recovery, or attachment feature.
- Turning off MFA because a login is inconvenient.
- Approving autofill on a lookalike domain.
- Keeping duplicate browser and manager stores without deciding which is authoritative.
- Treating a security score as proof that an account cannot be phished.
- Sharing a vault password through text, email, or a screenshot.
Frequently asked questions
What if I forget the master password?
Some zero-knowledge providers cannot reset it. Use the provider’s documented emergency or recovery option and keep recovery material separate from the vault. Do not assume support can see or restore the master password.
Should I import every old password?
Import what you need, then review duplicates and stale accounts. Delete unused accounts where possible and replace reused passwords for critical services first.
Is a password manager safe?
It can materially improve account security by enabling unique passwords, but it does not eliminate phishing, malware, lost-device, or recovery risks. Protect the vault account with a strong master passphrase, MFA, updates, and a tested recovery plan.
Do I need to change every password immediately?
No. Start with email, financial, recovery, administrator, and work accounts. Work through the remaining list in manageable sessions and respond promptly to breach alerts.
Bottom line
Set up the manager itself carefully, then use it to make every important account unique. Choose a compatible provider, create a long unique master passphrase, enable MFA, import cautiously, delete plaintext exports, verify autofill domains, and maintain a separate recovery plan. The quality of the setup matters more than a marketing “best password manager” label.
