Clarify how you will use it

Write down which devices you use for your accounts and whether any sign-ins genuinely need to be shared with another person. For a particular product, check supported devices, synchronisation arrangements and the recovery methods it provides. A managed work account may follow separate rules. Do not independently move organisational credentials into a personal vault without the appropriate authorisation.

Obtain the application or browser extension only from the official source identified by its provider. Check the publisher and read the setup instructions before entering important information. A familiar product name in a search advertisement is not sufficient evidence of origin. A small set of understood functions is enough to begin; numerous additional features do not establish suitability for your daily routine.

Protect the main way in

If the product uses a master password, make it long, unique and unused elsewhere. Follow the provider’s requirements and enable an additional sign-in check where offered. Store required recovery information so it remains available if a device is locked or lost, while keeping it protected rather than openly beside the computer. Think about both access and confidentiality when choosing that location.

Read specifically what happens if the master password is forgotten. Recovery possibilities differ; a provider cannot automatically unlock every vault. Record a supported recovery route and make sure you understand it. Instructions stored only inside the locked vault cannot help you regain access. Avoid exposing recovery keys during screen sharing or placing them in unprotected notes shared with other people.

Practise with one account

Choose an account whose temporary loss would not block an urgent task. Save the correct website address, username and existing password. Sign out and test signing in again using the stored entry. Check the address of the page you have opened, rather than relying only on its logo or familiar colours. A successful first test makes the later migration less confusing.

Then, where appropriate, generate a new unique password and change it through the service’s normal account settings. Confirm that the vault entry is current only after a successful sign-in. Avoid changing several important accounts simultaneously. Otherwise an error makes it harder to determine which password applies where. Automatic filling assists the process but does not replace checking the destination.

Bring it into everyday use gradually

Move additional accounts in small groups and remove stale duplicate entries only after checking them. If you import data, read warnings about the export format. An exported file may contain passwords without protection and therefore needs appropriately protected handling. Do not leave intermediate copies forgotten in Downloads or a shared folder, where they could expose the very information the vault is intended to protect.

Test access on a second intended device and check the vault’s locking behaviour. Keep the application updated and revise recovery details when devices or contact information change. A password manager reduces the burden of remembering different passwords, but cannot guarantee complete security. Unexpected sign-in requests, approval prompts and messages claiming to provide support still need independent scrutiny.

One thing to take away

Start with a low-stakes account and a checked recovery plan before moving more sign-ins.

A question or correction about this guide? ↗