How to set up a password manager the right way
Last year I helped my mother-in-law get back into her Gmail after someone reset it using a password she’d been reusing since roughly 2011. Same password on that account, on a shopping site that got breached in 2019, and on a forum she hadn’t logged into in five years. One leak, three accounts down. She’s not careless, she just never had a reason to change the habit until it cost her a weekend.
This is for anyone still relying on their browser’s built-in autofill, a notes app, or a password they can “remember” because it’s a variation on the same three words. It’s not for people already running Bitwarden or 1Password properly, you’re past this.
By the end you’ll have one encrypted vault, a unique password on every account that has one, two-factor authentication on the vault itself, and a plan for what happens if you lose your phone. Budget 60 to 90 minutes if you’ve got fewer than 100 saved logins. Longer if you’re the type who’s been saving passwords in Chrome since 2015.
what you need
- a password manager account: I’m using Bitwarden as the reference here because it’s free and open source, but everything below applies to 1Password too
- an email address you actually check, ideally not the same one tied to your most sensitive account
- your phone and your main computer, since you’ll install apps on both
- an authenticator app (Aegis, Raivo) or a hardware key like a YubiKey 5C, for 2FA on the vault itself
- your current saved passwords, exported as a CSV from whatever browser has them now
- a bit of paper or an index card for the emergency recovery sheet, this stays offline
- cost: Bitwarden’s free tier does everything in this guide; Premium is $10/year if you want file attachments and emergency access for more than one contact. 1Password runs $2.99/month for one person, $4.99/month for a family of five
step by step
1. pick your vault
Bitwarden or 1Password, and honestly either is fine. I run Bitwarden for myself and 1Password for a client’s small team, mostly because their office already had it. If you want the actual feature-by-feature comparison, I wrote one at /blog/bitwarden-vs-1password-in-2026. Create the account with a real email address you control.
Expected result: a confirmation email and a working login at vault.bitwarden.com or 1password.com.
If it breaks: confirmation email not arriving after a few minutes, check spam first, then try a different email provider. Gmail and Outlook both sometimes flag transactional mail from smaller password managers as suspicious.
2. build a master password you’ll actually remember
Don’t use a word plus numbers. Use a passphrase, five or six random unrelated words. NIST’s current digital identity guidelines (SP 800-63B) explicitly recommend length over complexity rules like forced symbols, which is the opposite of what most sites still demand of you. Bitwarden’s own CLI can generate one:
bw generate --passphrase --words 6 --separator -
That gives you something like harbor-violin-thicket-mango-drift-cobalt, which is easier to type on a phone keyboard than Tr0ub4dor&3 and harder to crack.
Expected result: a passphrase 25+ characters long that you can say out loud and remember after typing it five or six times.
If it breaks: if you genuinely can’t retain it after a day of use, write it on paper, lock the paper in a drawer, and destroy it once it’s memorized. Never save your master password in another app, a text file, or a photo.
3. lock the vault with 2FA
The vault itself needs stronger protection than any single account inside it, because it’s the one thing that unlocks everything else. Go to Settings > Security and turn on two-factor authentication. I use a YubiKey 5C for my vault and email, and an authenticator app as backup for everything else, the tradeoffs are covered in /blog/authenticator-apps-vs-hardware-keys. Save the recovery codes it gives you now, on paper, not in the vault you’re trying to protect.
Expected result: your next login prompts for a code or a key tap, not just the master password.
If it breaks: lost your 2FA device before you’ve set up a backup method, use the recovery codes from setup. If you didn’t save those either, most providers require identity verification through support, which can take days, so don’t skip this step.
4. install everything and turn off the browser’s own manager
Install the browser extension, the mobile app, and the desktop app. Then go into your browser’s settings and turn off its built-in password saving. Running two password managers side by side means two competing autofill popups and, worse, two separate copies of your passwords, one of them possibly syncing to your Google or Microsoft account without you thinking about it. This matters more depending on which browser you’re on, I go into it in /blog/firefox-vs-brave-for-privacy.
Expected result: the extension icon fills in logins; the browser’s native autofill prompt no longer appears.
If it breaks: both still popping up, check Chrome’s Settings > Autofill > Password Manager and switch it off explicitly. It doesn’t turn off just because you installed a competitor.
5. import your existing logins
Export your current passwords from your browser as a CSV, then import that file straight into your new vault.
bw import chromecsv ./chrome_export.csv
Once it’s imported and you’ve confirmed the count matches, delete the CSV file permanently, don’t just drag it to the recycle bin. It’s a plaintext list of every password you own sitting in your Downloads folder.
Expected result: your vault shows the same number of items as your old browser had saved.
If it breaks: fields import wrong, usernames in the password column or similar, check that the CSV headers match what the importer expects. Bitwarden’s import docs list the exact column format per browser, redo the export if it’s off.
6. run the built-in security audit
Bitwarden calls it Vault Health Reports, 1Password calls it Watchtower. Both flag reused passwords, weak ones, and logins that show up in known breaches, checked against Have I Been Pwned, Troy Hunt’s breach database. Go through the list and change the reused and breached ones first, weak-but-unique ones can wait.
Expected result: a report listing how many of your saved logins are reused, weak, or compromised.
If it breaks: the report times out or comes back empty on a large vault, wait a few minutes and rerun it. HIBP rate-limits bulk queries, and vaults with a few hundred entries can hit that.
7. turn on passkeys where they’re offered
Google, GitHub, Amazon, and a growing list of others now let you replace the password entirely with a passkey, a cryptographic key pair stored in your vault instead of a shared secret you type. The FIDO Alliance maintains the spec behind this. I’ve written more on whether it’s worth switching at /blog/what-is-a-passkey-and-should-you-use-one. For supported sites, add the passkey and let the login flow use Face ID or your fingerprint instead.
Expected result: logging in shows a biometric prompt instead of a password field.
If it breaks: passkey doesn’t sync to your other device, check your vault app is updated, Bitwarden needs 2023.10 or later, 1Password needs version 8. I’ll admit I still don’t use passkeys for either of my Singapore bank accounts, neither supports it yet, so it’s password plus hardware key there for now.
8. set up emergency access and a physical backup
Bitwarden’s Emergency Access and 1Password’s Emergency Kit both let someone you trust get into your vault if something happens to you, after a waiting period you control. Set one up, and separately print the recovery sheet 1Password generates (or write your own for Bitwarden) and store it somewhere offline, a safe, a drawer, not a photo on your phone.
Expected result: a named emergency contact configured, and a physical sheet with your account details and recovery codes stored somewhere that isn’t the vault.
If it breaks: you change your master password later and forget to regenerate the kit, the old sheet becomes useless. Reprint it every time the master password changes.
common pitfalls
- reusing the vault’s own master password anywhere else. It defeats the entire point, that password should exist nowhere but your head and, briefly, the paper you destroyed.
- not deleting the plaintext CSV after import. I’ve found these sitting in Downloads folders on client laptops months after “setup was done.”
- leaving browser sync running alongside the password manager, so Chrome is quietly uploading a second copy of your saved logins to your Google account without you noticing.
- setting it up once and never running the security audit again. Breaches happen constantly, a password that was fine in 2024 might be sitting in a dump by 2026.
- storing 2FA codes for your email or vault inside the same vault as everything else. If someone gets into the vault, they get the codes too. Keep that one on a separate authenticator app or hardware key.
scaling this
For one person, everything above is the whole job, done in an hour and maintained with an occasional audit.
For a household or a family of five to ten, both Bitwarden Families ($40/year for six users) and 1Password Families ($60/year for five) add shared collections, so the wifi password and the Netflix login live in a shared space while each person keeps their own private vault. This is also where the same principle applies if you’re juggling several separate identities, the antidetect browser crowd over at antidetectreview.org/blog run into exactly this problem managing dozens of profiles: one vault per identity, never share credentials across them, or the isolation you’re paying for is worthless.
Past 20 to 100 people, you’re into the admin console tier: SSO through Google Workspace or Okta, a company-wide policy that forces 2FA on every account, and provisioning tied to your actual offboarding process so a departed employee’s access dies the day HR flags it, not whenever someone remembers.
Past a few hundred, the password manager stops being a standalone tool and becomes one piece of a broader identity stack, SCIM provisioning, audit logs someone actually reviews, and usually a security team whose job includes owning this policy rather than it being one more thing IT bolts on.
where to go next
- /blog/authenticator-apps-vs-hardware-keys if you want to go deeper on which 2FA method to put on the accounts that matter most
- /blog/what-is-a-passkey-and-should-you-use-one for the longer case on whether to migrate off passwords entirely where you can
- /blog/asking-a-company-what-it-holds-on-you once your accounts are locked down, worth knowing what the companies behind them actually keep
More guides like this live at /blog/.
Written by Xavier Fok
disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-13.