Windows & Mac · Guide

How to Set Up a Password Manager the Right Way

Short answer

Pick one manager, create a long passphrase you never reuse, turn on two-factor authentication, import your browser-saved passwords, then replace reused passwords starting with email and banking.

Requirements

  • A password manager such as Bitwarden or KeePassXC
  • A passphrase you can memorize
  • An authenticator app or hardware key
  • About an hour for the first pass

Steps

  1. 1. Choose local or synced

    KeePassXC keeps a file you control and sync yourself. Bitwarden syncs through an encrypted hosted service. Pick based on whether you want to manage sync or not.

  2. 2. Create the master passphrase

    Four or five unrelated words are easier to remember and harder to crack than a short complex string. It must not be used anywhere else.

  3. 3. Turn on two-factor

    For a hosted vault, enable an authenticator app or hardware key immediately. For a local vault, consider a keyfile or hardware key as a second factor.

  4. 4. Import existing passwords

    Export from your browser, import into the manager, then delete the export file and clear the browser's saved passwords.

  5. 5. Fix the important accounts first

    Email, banking, and your phone carrier come first — those are the accounts used to reset everything else.

  6. 6. Set up recovery

    Write the master passphrase on paper and store it somewhere physically secure. There is no reset link for an encrypted vault.

Alternative methods

  1. 1. Use passkeys where offered

    Both Bitwarden and KeePassXC support passkeys, which remove the password from the login flow entirely on supporting sites.

  2. 2. Start with the browser's manager

    It is better than reuse, but it ties you to one browser and offers weaker sharing and auditing.

Troubleshooting

Autofill does not appear on a site

The saved URL probably does not match the login domain. Edit the entry and add the correct URI.

The import created duplicates

Sort by name and merge before you start changing passwords, so you do not update the wrong copy.

I am locked out of a synced vault

Without the master password there is no recovery by design. This is why the paper backup step matters.

Frequently asked questions

Is it risky to keep all passwords in one place?

The alternative in practice is reuse across dozens of sites, which is measurably worse. A strong master passphrase plus two-factor is the mitigation.

How often should I change passwords?

Change them when a service reports a breach or when a password is reused — routine rotation on a schedule is no longer recommended practice.

Reviewed by SoftNexi Editorial Team

Last verified: July 20, 2026