Clear, practical technology insights
Secure Your AccountsLesson 2 of 15

Set up a password manager

A password manager solves the memory problem that makes unique passwords difficult, but the vault becomes a high-value account of its own. A safe setup is more than installing an extension. You need a trustworthy source, a strong vault sign-in method, MFA, a recovery plan, correctly matched browser autofill and a controlled migration from old passwords. This lesson builds that system without assuming that one product is right for everyone.

14 min Beginner Secure Your AccountsReviewed 2026-07-30 00:00:00
Learning objectives

What you will learn

  • Evaluate a password manager using practical security and support criteria.
  • Protect the vault with a strong primary secret and MFA.
  • Import or add accounts without leaving unsafe exports behind.
  • Test autofill and recovery before relying on the manager.
Before you start

What you need

  • Access to your primary email account.
  • A supported phone or computer that receives security updates.

Choose a manager you can maintain

CISA recommends password managers because they can generate, save and fill long unique passwords, reducing the pressure to memorize or reuse them.

NIST authentication guidance supports long passwords and discourages composition rules that often lead to predictable patterns. A manager makes long random values practical.

Compare security update history, independent documentation, export options, device support and account-recovery design. A built-in browser or operating-system manager can be suitable for one ecosystem; a cross-platform service may be better when you routinely use several platforms.

Password manager vault workflow from product selection through recovery testing.
The vault reduces password reuse only when its own access and recovery are protected.

Protect the vault account

The primary vault secret must not be reused anywhere else. If the manager supports a passkey or security key, consider it. Otherwise use a long memorable passphrase and MFA. Protect the email account that receives vault recovery messages with equally strong authentication.

  1. 1

    Install only from the official store or vendor site.

  2. 2

    Create a unique vault passphrase that is not stored in the same vault as its only copy.

  3. 3

    Enable the strongest supported MFA method.

  4. 4

    Save recovery codes outside the primary device.

  5. 5

    Review trusted devices and remove old sessions.

  6. 6

    Set a reasonable auto-lock period for the device and environment.

Migrate accounts without leaving copies behind

Add the primary email and other high-value accounts first. If importing from a browser or another manager, remember that CSV exports are usually unencrypted plain text. Keep the export only as long as needed, import on a trusted local device and delete it from Downloads, cloud sync and recycle bins afterward.

Autofill is also a phishing defense when it refuses to fill on the wrong domain. Do not override that signal casually. A lookalike domain may display the same logo while the manager correctly treats it as a different site.

  1. 1

    Create or import a small test group first.

  2. 2

    Open each service through a known official address.

  3. 3

    Save the correct login URL with the entry.

  4. 4

    Change any reused password after the entry is safely stored.

  5. 5

    Verify autofill works only on the intended domain.

  6. 6

    Remove temporary export files and check synchronized folders.

Test recovery before depending on the vault

Read the provider recovery rules. Some zero-knowledge systems cannot restore the vault if every recovery method is lost. Others allow an emergency contact, account recovery key or trusted device. The correct choice depends on your risk and household needs, but it must be tested.

  1. 1

    Keep the current session open.

  2. 2

    Open a private window or second device.

  3. 3

    Complete a normal sign-in with MFA.

  4. 4

    Confirm where recovery codes or keys are stored.

  5. 5

    Document how a trusted person should respond in an emergency without giving them unrestricted daily access.

Verification checklist
  • The vault password is unique.
  • MFA and recovery codes are configured.
  • Temporary exports no longer exist.
  • Autofill does not fill on unrelated domains.
Hands-on practice

Migrate five accounts safely

Use a small migration to test the full workflow.

  1. 1

    Add primary email and four lower-risk accounts.

  2. 2

    Replace every reused password with a generated value.

  3. 3

    Test autofill on the official domains.

  4. 4

    Test vault sign-in on a second device.

  5. 5

    Confirm recovery materials are accessible without the primary phone.

  6. 6

    Delete any plain-text export used during migration.

Common mistakes to avoid

  • Reusing the vault password elsewhere.
  • Keeping an unencrypted CSV export indefinitely.
  • Saving the only recovery key inside the locked vault.
  • Ignoring an autofill domain mismatch.
Lesson recap

Key takeaways

  • A password manager reduces reuse but becomes a critical account.
  • Migration files and recovery methods need deliberate handling.
  • Domain-aware autofill can help expose phishing sites.

Frequently asked questions

Is a browser password manager safe enough?

It can be appropriate when the browser account, device lock, updates, MFA and recovery are well protected. Compare your platform needs and recovery model.

Should I memorize every generated password?

No. Memorize the vault access method and keep recovery material safe; let the manager store unique account passwords.

Evidence and updates

Sources and further reading

  1. Use Strong PasswordsCISA
  2. SP 800-63B: Authentication and Authenticator ManagementNIST
Finish this lesson

Ready to continue?

Mark the lesson complete so your Learning Path progress stays current on this device.