A password manager helps you use a different, strong password for each account without memorizing them all. To set one up safely, choose a manager that works on your devices, protect its vault login with multifactor authentication (MFA), move your accounts to unique passwords, and keep recovery information accessible. NIST recommends password managers for accounts that use passwords: NIST SP 800-63B Revision 4.
Choose a password manager that fits your devices and recovery needs
Before importing every login, check that the manager supports the computers, phones, operating systems, and browsers you actually use. CISA recommends checking compatibility and vetting the product and developer because the application will hold account credentials: CISA’s password guidance.
Compare the practical trade-offs rather than assuming one storage model is best for everyone:
- Cloud sync: Convenient when you need logins on several devices. Check which devices and browsers are supported and what account recovery entails.
- Local storage: Keeps the vault on your devices, but you are responsible for maintaining secure backups so a lost or damaged device does not leave you without your passwords.
- Vault protection and recovery: Confirm that the manager offers MFA and understand its recovery options before relying on it. Recovery and reset procedures vary by provider.
Use the provider’s current setup instructions for its vault credential. Do not reuse that credential on any other service.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Install the manager and protect the vault
- Install the manager’s official application on your supported devices and its browser extension, if you use one.
- Set up the vault credential as directed by the provider. Choose a credential you do not use anywhere else.
- Turn on MFA for the manager if available. Review the provider’s recovery instructions before adding all your accounts.
- Save any recovery information the provider supplies somewhere secure and separate from ordinary sign-in access. Make sure it remains accessible if your primary device is lost.
There is no universal password-manager recovery workflow. Follow the specific provider’s instructions rather than assuming that a reset, recovery code, or trusted device works the same way across services.
Move your accounts to unique passwords
Add your existing logins to the vault and replace reused or weak passwords with unique generated ones as you work through your accounts. Some services may limit password changes or impose their own requirements, so follow each site’s current instructions.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
NIST’s July 2025 SP 800-63B Revision 4 sets a 15-character minimum for passwords used as a single factor; it permits a minimum of eight characters when a password is used as part of MFA. The standard also says verifiers should not impose other composition rules. Those are requirements for verifiers under NIST’s standard, not a guarantee that every consumer website follows them. A manager’s password generator can make it easier to use a different password for every account without having to memorize each one.
Turn on MFA for important accounts
MFA adds another sign-in factor beyond the password. Enable it wherever available, prioritizing your password manager, email, financial accounts, and other accounts where unauthorized access could have a serious impact. CISA and the FTC recommend stronger options when a service supports them:
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
| Method | What to consider |
|---|---|
| Security key | CISA lists security keys among the strongest common MFA choices. The account and your device must support the key, and you should keep a recovery route available. |
| Authenticator app | The FTC identifies an authenticator app as safer than SMS or email codes when available. Check that you can retain access or recover it if you lose or replace your device. |
| SMS or email code | Use these if stronger methods are not offered, while recognizing that the FTC considers an authenticator app or security key safer when available. |
See CISA’s guidance on strong passwords and MFA and the FTC’s guide to multifactor authentication for more on available methods.
Secure your email account carefully
Email deserves special attention because password-reset links often arrive there. Use a unique password stored in your manager and enable MFA on the account. If someone gains access to your email, they may be able to use reset messages to reach other accounts.
Rank #4
Consider phishing-resistant sign-in where supported
A unique password is useful, but it does not make password sign-in phishing-resistant. NIST SP 800-63B Revision 4 states, “Passwords are not phishing-resistant.” Where an account supports FIDO/WebAuthn authentication, such as sign-in with a compatible security key, consider using it. Availability depends on the service and device. NIST explains the distinction in SP 800-63B Revision 4.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep recovery possible and maintain the setup
Find out which recovery codes, trusted devices, or account-recovery options your password manager provides. Store recovery information securely and separately from routine sign-in access, following the provider’s instructions. If you use a physical security key, preserve an account recovery route in case the key is lost.
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Change a password promptly when there is evidence it has been compromised. If that password was reused, change it on every other service where it appears. NIST says verifiers should not require routine password changes when there is no evidence of compromise; you do not need to rotate every password on a calendar schedule solely for the sake of doing so. Review alerts and security settings when services change their options.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

