How to Set Up a Password Manager: A Step-by-Step Guide
Author: Rasmus

How to Set Up a Password Manager: A Step-by-Step Guide


The average person has more than a hundred online accounts and reuses the same handful of passwords across them. That math is the problem: one small site gets breached, and the password you reused everywhere is now in a list being tried against your email, your bank and your social accounts.

A password manager breaks the cycle. It stores every login behind one strong master password, generates unique random passwords for each site, and fills them in for you. Setup takes one evening. Here is how to do it.

Step 1: Pick a password manager

All reputable managers work the same way: an encrypted vault that only unlocks with your master password. The differences are in where the vault lives and how much you want to pay.

  • Bitwarden — open source, apps for every platform, a genuinely useful free tier. The most common starting point.
  • 1Password — polished, paid, with good family and sharing features.
  • KeePass — the local-first option: your vault is a file on your own disk, no cloud store. Great if you prefer not to depend on an online service.
  • Your browser or phone built-ins — Google, Apple and browsers all ship one. Fine as a first step, but limited: lock-ins, weaker sharing and recovery, and they often only cover one platform.

Whichever you pick, install it on every device you actually use. A manager that is only on your laptop leaves your phone unprotected.

Step 2: Create a strong master password

Your master password is the single key to everything — and most managers cannot reset it for you. Treat it accordingly:

  • Use four or five random words (like harbor mask video clock). Longer beats complicated: a 16-character passphrase of words is far stronger than a 12-character jumble, and easier to type on a phone.
  • Never reuse it. Not for email, not for a bank, not for anything else.
  • Write it down once, on paper, and store it somewhere safe (a locked drawer or a safe). This is not a security risk — it is a recovery plan.

If you can remember it, it is probably fine; if you can remember all of your passwords, they are not.

Step 3: Install the apps and extension everywhere

Install the phone app on your phone, the desktop app and the browser extension on your computer. Then:

  • Sign in on each device. Some managers want a confirmation on the first device — that is the point.
  • Enable biometric unlock (fingerprint or face) on your phone. It is faster and, for most people, more secure than a short PIN.
  • Make autofill the default in your phone settings, so tapping a login field offers the vault entry instead of keyboard suggestions.

Step 4: Import the passwords you already have

You do not start from zero. Every browser can export your saved passwords, and every manager can import that file:

  1. Export your passwords from your browser’s password settings page.
  2. In the manager, choose “Import” and pick the browser format. Most managers detect duplicates.
  3. Delete the export file afterwards and empty the recycle bin — that file is every password you own in plain text.
  4. Turn off the browser’s own autofill once everything is in the vault, so the two systems do not fight each other.

Step 5: Change your most important passwords first

Trying to redo all 100 accounts tonight would take hours. Prioritize:

  1. Email first. Your email can reset almost every other account. If an attacker owns it, they own you.
  2. Banking and payment accounts.
  3. Cloud storage and anything with your documents or photos.
  4. Social and messenger accounts.
  5. Everything else can follow over the next few weeks.

If you also have smart home devices with their own logins — cameras, plugs, hubs — add them to the list; the home IoT security guide explains why those accounts matter too.

While you are at it, generate a new random password for each of these — one keystroke in the manager, and it is done.

Step 6: Let the generator and autofill do the work

From now on, the manager generates when you register, and fills when you return:

  • Never type a new password manually if you can avoid it — the built-in generator makes 16-character random passwords that look like noise.
  • Unique per site is the rule. One site’s leak then tells an attacker nothing about the rest of your accounts.
  • Autofill only works where the extension is active — the universal device access guide covers setting up your accounts on every device you own.

Step 7: Turn on two-factor authentication for the critical accounts

A password manager solves the reused-password problem; two-factor authentication (2FA) solves the stolen-password problem. For email, banking and cloud accounts, enable 2FA if it is available:

  • An authenticator app (TOTP codes) is the standard choice. Many password managers can store the codes themselves — practical, though it puts your 2FA and your passwords in the same vault.
  • Store the recovery codes you get when enabling 2FA. Put them in the manager’s secure notes or print them; without them, a lost phone can lock you out of your own account.

Step 8: Set up recovery and a backup

This is the step people skip, and the one they regret. Before you switch everything over:

  • Save your recovery code (the one the manager gives you for losing your master password).
  • One encrypted backup export from the manager, stored offline (a USB stick in a drawer). Some managers do this automatically.
  • Share an emergency access key with a trusted person or store a note with your paper copy of the master password — decide for yourself what fits, but decide now, not after a locked-out evening. Whatever you choose, keep the details somewhere you can find them; the personal knowledge base guide shows a simple note system that survives.

Step 9: Run the audit and keep it clean

Once a month, open the manager’s health or security report. It will show you:

  • Passwords you still reuse across sites — fix them one at a time.
  • Weak or short passwords — regenerate.
  • Breach alerts — if a site you use has been compromised, change that password immediately. Services like Have I Been Pwned check your email address against known breaches; most managers do this check for you.

A note on passkeys

Passkeys — login with a physical security key or your device’s biometrics instead of a password — are already supported by most managers and browsers. They are worth enabling where offered, especially for email and banking. They are not a replacement for a password manager yet; they are another tool it stacks with. And if you work from home, the home office setup guide has a short network-security section that pairs well with this one.

Quick wins checklist

  • One password manager installed on every device
  • Master password: 4–5 random words, unique, written down on paper
  • Browser export imported, export file deleted
  • Email, banking and primary accounts changed to unique passwords
  • 2FA enabled where it matters, recovery codes saved
  • Recovery code + offline backup in place
  • Monthly audit set as a recurring reminder

You do not need to be a security expert to secure your accounts. You need one evening, one good master password, and a manager that does the remembering for you. Your future self — the one whose email did not get hacked — will thank you.

Hero image: Yuri Samoilov, CC BY 2.0, via Wikimedia Commons.