Activation Hub Online Blog
Guides

Setting up a password manager without locking yourself out

The hard part isn't moving your passwords in. It's the recovery plan — what happens when you lose your phone, forget the master password or the service changes its terms.

A person typing on a laptop at a bright desk

A password manager solves the problem of remembering dozens of unique passwords by replacing them with one. That's also its single point of failure. Moving your logins in takes an evening. The part that deserves more thought is what happens when something goes wrong: a lost phone, a forgotten master password, or a service you no longer want to use.

This guide works through the setup in the order that avoids lock-outs, with the recovery plan built in from the start rather than added later.

Choose where your passwords will live

There are two broad options. The first is the manager built into your platform or browser: the Passwords app on Apple devices, Google Password Manager in Chrome and Android, and the equivalents in other browsers. These are free, already installed and sync automatically. Their limit is that they work best inside one ecosystem; if you use an iPhone and a Windows laptop with a non-Apple browser, you'll hit friction.

The second is a standalone manager that runs on every platform. These cost money on most plans, and add features such as secure sharing with family members, emergency access and more flexible exporting.

Either is a large improvement over reusing passwords. Before committing to a standalone service, check three things on the provider's own site: which platforms it supports, how account recovery works, and how you export your data if you leave. That last one is the most overlooked.

Create a master password you'll actually remember

The master password has to be strong, and it has to survive six months of you not typing it because your phone unlocks the vault with your face. The practical answer is a passphrase: four or five unrelated words, such as a random combination you can picture. Length does more than symbols.

Then write it down. That sounds wrong, but a written master password stored at home — in a drawer, with other important papers — protects against the most common real failure, which is forgetting it. The people who might read a piece of paper in your house are not the people trying to break into your accounts.

For the first few weeks, type the master password deliberately every few days instead of relying on biometrics. It's how it moves into memory.

Set up recovery before you import anything

This is the step to do first, while you still have access to everything. Most managers offer some combination of the following. Set up every one your manager supports.

  • Recovery codes or an emergency kit. Many standalone managers generate a recovery document or secret key when you create the account. Print it, and store it with your written master password.
  • A recovery contact. Some platforms let you nominate a trusted person who can help you regain access without being able to see your passwords. Apple accounts, for example, support a recovery contact in the account settings.
  • Emergency or legacy access. This lets a named person request access to your vault if something happens to you, usually after a waiting period you can refuse. It's worth setting up for a partner or family member.
  • Two-factor on the manager account itself, with its backup codes saved on paper. Which second factor to choose is worth a few minutes' reading.

Then test it. Sign out on one device and sign back in using only what's written down. If that fails now, it would have failed in an emergency.

Move your passwords in, gradually

Most managers can import from your browser's saved passwords directly, or from a CSV file you export from the browser. Once the import is done, delete that CSV file straight away and empty the bin: it's every password you have in plain text.

After importing, turn off the browser's own password saving if you've chosen a separate manager, so you don't end up with two out-of-sync copies.

Don't try to change every password in one sitting. Start with the accounts that matter most — email, banking, your phone's platform account — and give each a new, generated password. Then work through the manager's security report, which will flag reused and weak passwords, a few at a time as you log in to things over the following weeks.

Plan for a lost or replaced phone

If your phone is the main device that unlocks the vault, losing it is the scenario to rehearse. Ask yourself: with a new phone and nothing else, could I sign back in? You'll need the master password, whatever second factor protects the manager account, and possibly a recovery code.

If your second factor is an authenticator app on that same phone, you have a loop: the codes are on the device you lost. Break it by keeping the backup codes on paper, or by registering a second factor such as a security key or a passkey on another device.

Keep at least one other signed-in device where possible — a laptop or tablet — so a single loss doesn't take out access completely.

Plan for leaving the service

Terms, prices and features change. Once a year, export your vault and check that the file is readable, so you know you can move if you need to. Store the export encrypted, or delete it after checking; an unencrypted export is as sensitive as the vault itself.

Be aware that passkeys don't yet move between managers as easily as passwords do. A standard for transferring them is being adopted, but support is uneven. If you rely heavily on passkeys, check what your manager can export, and keep a password or other sign-in method on important accounts as a fallback.

If you pay for a manager, the renewal and any refund are handled by the provider, or by the app store if you bought it through one. Diarise the renewal date so a price change doesn't arrive unannounced.

A five-minute checklist

  1. Master password written down and stored at home.
  2. Recovery code or emergency kit printed and stored with it.
  3. Two-factor on the manager, with backup codes on paper.
  4. Recovery contact or emergency access set up, where available.
  5. Sign-in tested from scratch on a second device.
  6. Any imported CSV files deleted.
  7. An annual reminder to export and check your vault.

Get these right and a password manager is one of the most effective security changes you can make. Skip them and it's a very tidy way to lose everything at once.