Choose a password manager

Select a tool that can generate and store a different strong password for every account.

Difficulty
Beginner
Time
About 15 minutes
Platforms
Windows, macOS, Linux, Android, iOS

A password manager makes it practical to use a unique, randomly generated password for every account. If one service is breached, attackers cannot reuse that password elsewhere.

What to look for

Choose a well-established password manager that:

  • supports every device and browser you regularly use;
  • encrypts your vault before it leaves your device;
  • supports two-step verification or passkeys;
  • can export your data in a usable format;
  • explains its security design and how it responds to vulnerabilities;
  • receives regular security updates.

Convenience matters. A technically impressive tool that you cannot use reliably is unlikely to improve your security.

Built-in, cloud or offline?

Browser and operating-system password managers can be a good starting point, particularly when you use one device ecosystem. Independent cloud-based managers usually support a wider range of devices and browsers. Offline managers give you more control over where the vault is stored, but make synchronisation and backups your responsibility.

There is no universally correct choice. Base the decision on your security plan, devices and ability to maintain backups.

Create a strong master password

Your master password protects the whole vault. Use a long, unique passphrase that you have never used elsewhere. Do not base it on a quotation, lyric or personal information that someone could discover.

Save any emergency or recovery material somewhere secure and separate from your everyday devices.

Secure the account

Enable the strongest two-step verification method the service supports. Save recovery codes before adding the rest of your accounts.

Configure automatic locking so the vault does not remain open indefinitely on an unattended device.

Migrate gradually

Start with your primary email, financial accounts and other accounts that could be used for recovery. Let the manager generate a new password for each one, then confirm the new password was saved before signing out.

Do not rush to change hundreds of accounts at once. A careful migration is safer than losing track of which credentials were updated.

Back up and test

Understand how you would regain access after losing a device. If the manager supports an encrypted export, create one periodically and store it securely. Treat an unencrypted export as highly sensitive and delete it safely after use.

Sources and further reading

This page was last reviewed on 26 July 2026