RAZIBINTERNET INDEX Suggest a resource

Account security

How to Set Up a Password Manager Without Losing Access

Move your logins into a password manager, replace reused passwords and build a recovery plan without locking yourself out.

A password manager becomes useful when it replaces the habit of remembering one password and changing the last few characters for every website. It becomes dependable when you can still open it after replacing a phone, forgetting a device PIN or losing access to your usual email address.

Start with a few important accounts rather than importing everything and immediately deleting the old copies. This guide uses a staged migration: prepare the vault, move a small set of logins, test them and then clean up. You do not need to finish every account in one evening.

Choose around the devices you actually use

Write down your main computer, phone and browser. Check that your chosen manager supports those devices, offers a practical recovery method and lets you export your information in a format you could use elsewhere. A polished phone app is not enough when you also need access from a Linux desktop or a shared family computer.

Decide whether you need cloud synchronization or a locally stored vault. Cloud sync can make everyday use simpler; a local vault gives you responsibility for copying and backing up its database. Neither choice removes the need for updates, a good unlock secret and a recovery plan. CISA's password-manager guidance discusses that convenience and maintenance trade-off.

Use the developer's website or an official app-store listing to find the installer. Do not install a lookalike extension from an advertisement. Our privacy and security directory can help you find tools, but follow through to the provider's own documentation before choosing one.

Protect the vault before filling it

Create a long, unique master passphrase if the manager uses one. It should not also be the password for your email, laptop or shopping account. Avoid publishing an example phrase and then using that exact phrase as your secret. Generated words need to come from a suitable random generator, not a memorable quotation.

Set a vault-lock timeout you can live with. Locking when the device sleeps is a useful starting point on a laptop. An always-unlocked vault on a shared desktop defeats much of the separation you are trying to create.

Enable the manager's supported second factor, then save its recovery material outside that same locked vault. Read how to store recovery codes before continuing. You need a route into the vault that does not require first opening the vault.

Move five accounts first

Begin with primary email, the account that syncs your phone, your main shopping account and two ordinary services. Leave especially sensitive work accounts alone until you have checked your employer's rules.

For each entry, save the real login URL, username and current password. Use a clear title such as “Personal email” rather than a vague domain name when several family accounts use the same service. Add a short note about the recovery method, but do not turn that note into an unprotected duplicate of every secret.

Bitwarden's web-app guide shows how a login record separates its name, username, password and website address. The same distinction is useful in other managers. Saving the correct website helps prevent confusing similar account names or trying an old login on the wrong service.

Now sign out of one low-risk account and sign back in using the saved entry. Keep a working session on another trusted device while you test your main email. This is a controlled check, not an invitation to close every session at once.

Change passwords at the website, not just in the vault

Editing a saved entry does not change the password held by the website. Open the account's own security page, generate a unique replacement and complete the site's change process. Then confirm the vault contains the new value.

Use the longest generated password the service reasonably accepts without silently truncating it. Follow the site's stated restrictions rather than forcing one universal format onto every service. Test the new login before moving to the next account.

Prioritize passwords that are reused, exposed in a breach or protecting important recovery accounts. See what to do after a breach alert for the order of work. There is little value in changing dozens of strong, unique passwords simply to meet an arbitrary monthly ritual.

Treat imports and exports as sensitive files

Bulk import can save time once you understand the manager. Read the import instructions for the exact source and destination products. Exported CSV files commonly contain readable credentials, so check the actual format instead of assuming a password-manager file is encrypted.

Create a temporary working folder outside shared or automatically synchronized locations. Import once, inspect several entries and look for duplicate accounts or missing notes. Avoid forwarding the export through email to move it between devices.

When the import is confirmed, remove the temporary file and its obvious duplicate downloads. Emptying the recycle bin is useful housekeeping, not a guarantee that every historical backup has been erased. For future backups, choose an encrypted export when supported and understand how you would restore it.

Make recovery understandable to your future self

A recovery plan needs the account address, the manager you use, the location of recovery material and any essential steps that are easy to forget. It does not need to be a public document or a note pinned to the laptop.

For example, 1Password's Emergency Kit records account details and provides space for the account password. Other products use different recovery arrangements. Follow your provider's process rather than assuming the same kit or recovery code works everywhere.

Keep a protected copy somewhere you could reach if your phone were lost. Check it after changing the manager's master password or recovery settings. A carefully stored but obsolete printout is not a working backup.

Remove old habits only after the new ones work

Once the vault works on your normal devices, stop saving new passwords in several competing places. Decide whether the browser or the separate manager will handle passwords, then disable unwanted save prompts. Do not delete the browser's old entries until you have checked the migrated records.

Use separate OS accounts for people sharing a computer. Separate browser profiles help with organization, but are not a substitute for access controls between users.

Keep a small migration list and cross off accounts as you verify them. The useful finish line is not an empty list of warnings. It is having unique credentials, working recovery and a routine that is easier than reusing passwords.

Sources and further reading

  1. Bitwarden: Create a login and secure your vault Consulted 28 September 2026.
  2. 1Password: Prepare an Emergency Kit Consulted 28 September 2026.
  3. CISA: Password managers and strong passwords Consulted 28 September 2026.

Consult the linked documentation for current details. Settings, availability and interface labels may change.

Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.