Set up a password manager

Personal setupTools · about 15 min · Everyone — the safety net behind every other account

Setting this up for your organization?Share credentials with your team using LastPass

A password manager remembers a unique strong password for every account so you don’t have to — and it’s the safest place to store your MFA recovery codes. Take a holistic approach: have one tied to the mobile device you carry, plus the one in your computer’s browser.

Tied to your phone: Apple Passwords / iCloud Keychain on iPhone & Mac, or Google Password Manager, which is built into Android. On your computer, the browser-profile manager — Chrome signed into Google, or Edge signed into Microsoft — saves passwords and backs up bookmarks (see the Chrome and Edge guides).

LastPass is a third-party manager that works universally across every browser and device. Being third-party, it has some native-support limitations, and most people won’t need it at first — but it becomes valuable at the organizational phase because it supports credential sharing across a team. Advanced users adopt it then.

One secured vault, a unique password everywhere

Whether it’s your browser’s built-in manager (unlocked by your Google or Microsoft account) or LastPass (unlocked by one master password), the rules are the same: a different strong password for every site, MFA turned on for the account behind the manager, and your MFA recovery codes stored inside it.

  1. 1

    Pick your managers (mobile + computer)

    On your phone, use the one tied to your device: Apple Passwords / iCloud Keychain on iPhone, or Google Password Manager on Android (both are already built in — just turn on sync).

    On your computer, use the browser-profile manager — Chrome signed into Google, or Edge signed into Microsoft (see those guides).

    Power option (advanced / organizational phase): install LastPass (browser extension + phone app) for cross-platform use and team credential sharing later. Choose a strong, memorable master password — if you forget it, no one can recover the vault.

  2. 2

    Secure the manager itself with MFA

    The manager holds the keys to everything. Make sure the Google or Microsoft account behind it — or your LastPass account — has an authenticator app turned on (see the MFA guide).

  3. 3

    Let it save and generate passwords

    As you sign in to sites, let the manager save the password. When creating new accounts, use its generate password button for a strong unique one.

  4. 4

    Never reuse the same password across services

    Use a different password for every account — never the same one twice. When passwords are reused, a breach at one weak site hands attackers the key to all your other accounts (this is called *credential stuffing*). A password manager exists precisely so you never have to remember or repeat one.

    Be most careful with your email and bank accounts. Your email is usually the ultimate recovery method — “forgot password” links and many MFA resets land there — so whoever controls your email can take over almost everything else. Banking and financial logins protect real money. These must have unique, strong passwords of their own (and MFA turned on), never shared with any other site.

    If you’ve been reusing a password, change it on the important accounts first (email, then bank, then anything financial), letting the manager generate a fresh unique one for each.

    Rule of thumb: if the same password would unlock both a random shopping site and your email or bank, that password is already too risky — give email and bank their own.

  5. 5

    Know how to actually see a saved password (not just autofill)

    Every one of these managers lets you reveal a stored password after you re-confirm it’s you (Face ID / fingerprint / device PIN / your account password) — you’re not stuck with autofill-only. You’ll need this when signing in on a device the manager can’t autofill into, or when adding a teammate to a shared account.

    Apple Passwords / iCloud Keychain: open the Passwords app (iPhone: Settings → Passwords; Mac: Passwords app), authenticate with Face ID / Touch ID / your passcode, tap the entry, then tap the password to reveal or copy it.

    Google Password Manager (Android/Chrome): go to passwords.google.com or Chrome → Settings → Google Password Manager, pick the site, and tap the eye icon — it asks for your phone screen lock or Google password first.

    Edge (Microsoft): Edge → Settings → Profiles → Passwords, choose the site, and click the eye icon; Windows asks for your Windows Hello PIN / account password to show it.

  6. 6

    Store your MFA recovery codes here

    Save each account’s recovery codes (from the MFA setup) in the manager — a secure note in LastPass, or your browser/Google account’s secure notes. This is what saves you when you lose or replace your phone.

    Passwords + recovery codes in one secured, backed-up vault = you can recover any account from any device.

Common questions

Why does it matter if I reuse one strong password everywhere?

Because you don’t control how every site stores it. When one site is breached — and breaches happen constantly — attackers take the leaked email + password and try it automatically on hundreds of other services (credential stuffing). One reused password turns a single breach into a break-in everywhere. It’s especially dangerous for your email and bank: email is the recovery channel for most of your other accounts, and bank logins guard real money. A manager makes a unique password per site effortless, so there’s no reason to reuse.

Built-in browser manager or LastPass — which?

Start with the built-in manager in your Chrome or Edge profile; it’s free and automatic. Add (or move to) LastPass when you need the same logins to work across many browsers/devices, or to share credentials with your team at the organizational phase.

What happens to my passwords if I lose my phone?

This is the whole reason FFC insists on a holistic setup with sync turned on. Apple Passwords (iCloud Keychain) and Google Password Manager both sync to your account in the cloud, so signing into iCloud or your Google account on a replacement phone restores every password and passkey — provided sync was on before you lost the device. The real danger is a manager that only kept passwords locally with no backup: if that device is gone, so are those passwords. So (1) keep iCloud Keychain or Google sync enabled, (2) keep a second copy on your computer’s browser profile, and (3) store each account’s MFA recovery codes in the vault, so even if you’re locked out of one factor you can still get back in.

Next setup guides

Where you’ll use this

This account is a starting point for these volunteer training tracks:

Stuck on any step? Text Clarke Moyer at (520) 222-8104 — every step is meant to be simple, so if something doesn't match what you see, ask.