Digital Safety & Privacy

Password Manager Guide: How to Choose, Set Up, and Recover Safely

Evaluate storage model, devices, sharing, recovery, and export, then migrate accounts to unique credentials without creating a lockout.

What this guide helps you do

Adopt a password manager with a tested recovery plan and unique passwords for important accounts.

A password manager helps create and store a unique credential for each account so one breach does not unlock everything else. The security benefit depends on setup, device protection, recovery, and whether you actually replace reused passwords.

Understand what the manager changes

Instead of memorizing many passwords, you protect the manager with one strong master credential and the security of your devices and account. The manager can generate random passwords, fill the correct site, warn about reuse, and sometimes store passkeys or secure notes. It does not make phishing, malware, or account recovery irrelevant.

Choose using operational questions

AreaQuestions
DevicesDoes it support every browser and device you actually use?
SecurityWhat protects stored vault data, sign-in, devices, and recovery?
RecoveryWhat happens if you forget the master credential or lose every device?
SharingCan families or teams share selected items without sharing the vault login?
PortabilityCan you export and delete your data in a usable, protected format?
SupportAre documentation, security notices, and support channels clear?

Create a strong master credential

Use a long, unique credential that has never protected another account. Follow the manager's current guidance and favor length over hard-to-type substitutions. Do not store the only copy in an unlocked note, email draft, or photo. Never give it to support or enter it after following an unexpected link.

Secure the manager account and devices

Enable the strongest practical multifactor method, keep recovery codes offline, update devices and extensions, use screen locks, and remove old sessions. Browser autofill should match the expected domain; stop when it does not. The MFA guide compares common methods and recovery.

Plan recovery before migration

  • Record the official recovery process
  • Store recovery codes in a protected offline place
  • Identify a trusted emergency-access option if appropriate
  • Test access on a second authorized device
  • Document how family or business continuity works
  • Know whether the provider can recover an encrypted vault

Migrate the highest-risk accounts first

Start with primary email, financial services, cloud storage, domain registrar, mobile carrier, work administrator, and the password manager itself. Replace reused passwords with generated unique values, confirm sign-in, update recovery details, enable MFA, and save backup codes before moving on.

Handle imports and exports carefully

Imported CSV files may contain every password in readable text. Perform the import on a trusted device, confirm the records arrived, then securely remove the export according to the device and storage system. Treat future exports as sensitive backups; do not leave them in Downloads or ordinary cloud folders.

Use sharing features instead of shared passwords

When several people need an account, prefer individual accounts and role-based access. If a credential truly must be shared, use the manager's controlled sharing, restrict recipients, rotate it when membership changes, and keep an owner. Do not send passwords through chat or spreadsheets.

Respond to a warning or breach

Verify notices through the official app or site. Change the affected credential, revoke sessions, review recovery and MFA settings, and replace any reused values. If the manager account itself may be compromised, follow its incident guidance from a trusted device and prioritize email and financial accounts. Use the phishing inspection steps before acting on a security alert.

CISA's public guidance recommends long, random, unique passwords and a password manager. The goal is not a perfect vault on day one; it is steadily eliminating password reuse while preserving recovery.

Sources and further reading

Primary and contextual sources used to verify definitions or give readers a relevant next resource.

  • CISA Secure Our World Official guidance recommending long, random, unique passwords and use of a password manager.
IE

Prepared and reviewed by

Infortified Editorial Team

Research-led guides with explicit scope, source checks where facts require them, and an independence review before publication.

Search Infortified

Find a practical answer

Start typing to search all guides.

Open full search