Skip to content
BeginnerSeveral short account sessions

Password, Passkey and Recovery Setup

Prioritize important accounts, adopt unique credentials or passkeys, enable supported MFA, and verify service-provided recovery methods.

security beginnersbreach victimsfamily IT admins

Workflow

  1. Identify accounts and recovery dependencies

    List service names and review status, starting with email, password management and accounts whose loss would block other access. Use your trusted password manager’s own review features when available.

  2. Set unique credentials or supported passkeys

    Choose a password manager that meets your device, recovery and sharing needs, or use an approved existing manager. Replace reused credentials at the actual service and save the new entry securely. Where supported, evaluate a passkey and its recovery path.

  3. Enable supported additional authentication

    Open the service’s security settings and follow its MFA or passkey setup. Prefer phishing-resistant options when supported. Register only devices or authenticators you control and understand how they are backed up.

  4. Retain service-provided recovery methods securely

    Use the provider’s actual recovery options, which may include issued backup codes, another authenticator or an account recovery contact. Store them according to your manager or organization’s recovery plan and ensure a lost device will not remove every route.

  5. Verify access and retire obsolete methods carefully

    Use a separate authorized session or device to verify the new sign-in path while retaining a working session until setup is confirmed. Revoke obsolete sessions or methods after reviewing dependencies. Record completion and unresolved recovery issues.

Tools Used

Checklist

0 / 5 completed

Loading your checklist…

Planning

Setup

Recovery

Validation

Review

Reference Materials

Unique passwords and managersTip

CISA recommends strong, unique passwords and a password manager to create and retain them. The manager and its recovery arrangements also need protection.

MFA and phishing resistanceTip

CISA explains that additional authentication strengthens account protection and recommends phishing-resistant MFA where available. Supported methods and recovery details differ by service.

Recovery acceptanceTable

Verify the real service configuration.

CheckEvidence to keep
CredentialNew sign-in succeeds through the intended method
Additional factorRegistered authenticator works on the service
RecoveryProvider-issued method retained through an independent access path
Review notesStatus and follow-up only; no secrets
  • Plan for the lost device

    Check that recovery still works when the phone or computer normally used to sign in is unavailable.

Safety Notes

  • Never share live passwords, authentication prompts, passkeys or recovery codes with someone claiming to verify an account.