1Password is (probably) the best password manager for home and work
An operator’s opinion: why 1Password is my default for personal use and small businesses, including the isolated Families account that comes with Business and MSP-provisioned seats.

If your logins live in a spreadsheet, a browser profile, or one person’s head, you do not have a password strategy. You have a breach waiting for a forward — whether that is the bank at home or payroll at the office.
I recommend a real password manager to almost everyone I work with. When they ask which one, my default is 1Password, for personal use and for small businesses. That is an opinion, not a lab bake-off. Bitwarden is a strong second. Chrome, Edge, Safari, and “we use LastPass because we always have” are not in the same conversation.
The operating rule is simple: personal items stay private, and company items that must be shared live in a team vault with deliberate permissions. This is the product call — including the part most people miss: a 1Password Business seat (including seats your MSP provisions) comes with a complimentary, isolated personal Families account.
What “best” means here
Best at home is the tool you and a spouse will actually open on a phone and a laptop, that can share the Wi‑Fi and the streaming logins without a group text, and that still works if one of you loses a device.
Best for a 5–50 person shop is the tool people will actually use on Windows, Mac, and a phone, that IT can offboard in an afternoon, and that does not turn shared firewall logins into a Teams chat.
1Password wins both jobs more often than anything else I deploy. The same apps. Two accounts. That is the point.
Personal: why I want it at home
People finish setting it up. The desktop app, browser extension, and mobile apps are boring in the good way. A vault nobody opens is a spreadsheet with extra steps.
The Secret Key is a real design choice. 1Password encrypts vault data with a combination of the account password (something you memorize) and a Secret Key (a long key created on your device that 1Password says they do not have and cannot recover). Official write-up: About your Secret Key. Keep the Emergency Kit. If you lose both the password and the kit, 1Password cannot shrug and reset you. That is the point.
Watchtower nags you about the right things. Weak, reused, and breached passwords, plus missing MFA on saved sites. See Watchtower. You still have to rotate the bad passwords. The report is not the fix.
Travel Mode is the feature I wish more vendors copied. It removes vaults from the apps except ones marked safe for travel. Documented here: Travel Mode. Useful when you do not want the tax-prep logins sitting on a laptop that is about to go through a bag check.
Families is how households should share secrets. A Families account is yours (or a family organizer’s), not your employer’s. Private vaults per person, shared vaults for the stuff everyone needs, and you can invite the household without giving them the work firewall.
If you are buying 1Password only for home, Families (or Individual, if you truly live alone and will stay that way) is the SKU. Do not put the company Microsoft 365 admin password in a personal account you will later mix with work. And do not use the browser’s Save prompt as a substitute — browser-saved passwords are not a business control, and they are a weak personal control too.
Business: why it is my default at work
Sharing is built for work, not “forward the CSV.” Shared vaults, groups, and the ability to recover or suspend a person are why you buy the business SKU. Personal free accounts mixed into company logins are how offboarding fails. 1Password’s business security practices are worth a one-hour read before you invite the whole office.
Watchtower rolls up across shared vaults. Business accounts can see weak and reused passwords where they actually hurt. Watchtower reporting still requires someone to change Welcome123.
Travel Mode can be managed. Business admins can turn it on for someone who is about to travel. Same docs as above.
It covers the messy middle of SMB life. One owner, a spouse who pays bills, three staff, a bookkeeper, and an MSP. That is a 1Password shape: Business for the company, Families for the household, both in the same apps.
The included isolated personal account (Business and MSP)
This is the feature I explain in every kickoff.
1Password Business includes a complimentary 1Password Families membership for every team member. 1Password documents this as a first-class part of Business, not a coupon in a PDF nobody reads: About 1Password Business and Get a free Families membership.
It is isolated. You redeem it by linking subscription status. 1Password is explicit: only the subscription status is linked. Ownership and access rights are not. The family account belongs to the family organizer. The business cannot access or manage it. Employers do not get visibility into what you store there. Official language is on that same support page and in 1Password’s work vs personal write-up.
MSP-provisioned Business is the same product. 1Password Enterprise Password Manager — MSP Edition is how MSPs provision and manage 1Password Business for clients (console, technician permissions, consumption billing). Client users are Business users. They get the same complimentary Families benefit. 1Password’s MSP collateral calls it a free Families plan for every user for personal use. The MSP can administer the company’s Business instance. The MSP cannot open your personal Families vault. That is the isolation you want: work secrets in the tenant your IT or MSP can offboard; Netflix, the mortgage portal, and the family group chat logins in an account that stays yours.
When you leave the company, the personal account does not vanish. 1Password’s support article: if you are removed from the Business account, the Families account unlinks and enters a complimentary trial. Add a payment method if you want to keep Families on your own dime. Print the Emergency Kit either way.
Do the split on purpose. Work logins, client admin, shared infrastructure: Business vaults. Personal banking, medical portals, household Wi‑Fi: Families. Sign into both accounts in the apps. Drag items that landed in the wrong place. Do not “just use the Employee vault for everything” because it was already open.
What I tell people who want cheaper
Bitwarden is the honest runner-up at home and at work. Open source, Organizations for sharing, and a price that is easier to swallow. If a household or a shop will actually administer collections, enforce MFA on the vault, and not cheap out into a two-person free org for twenty employees, Bitwarden is a respectable default. Start from Bitwarden’s Organizations docs, not a random YouTube setup.
I do not pick Bitwarden because 1Password is “insecure.” I pick 1Password because fewer rollouts stall on UX, recovery, and “how do I get this on the other laptop.” If you already live in Bitwarden and it is healthy, I am not going to rip it out for brand preference.
KeePass-style local files are fine for one careful person. They are a disaster for a household and worse for a team.
Apple Passwords, Google Password Manager, and Edge’s built-in store are convenience features tied to a consumer identity or a browser profile. They are not a family vault with offboarding, and they are not a company vault. See the browser-saved passwords piece.
What I will not recommend as a default
I still see LastPass in the wild because it was the name people knew. LastPass publicly described a 2022 incident chain in which attackers later accessed cloud storage that held customer vault backups — including unencrypted metadata such as URLs plus encrypted secret fields. Read their December 2022 notice and the March 2023 update. Encrypted-at-rest is not the same as “the backup was never stolen.” Trust is part of the product. I do not spend political capital putting a shop — or a household — back on LastPass.
How I actually roll it out
Home only
- Buy Families (or Individual if that truly fits).
- Turn on MFA before you import anything that matters.
- Move the logins that would ruin a week: banking, email, Apple/Google account, IRS/state, medical.
- Shared vault for household secrets. Private vaults for the rest.
- Print Emergency Kits. Store one copy the way you would store a will — not only on the laptop that already has the vault.
Work (including via an MSP)
- Buy Business, or take the Business instance your MSP provisions. Not a pile of personal subscriptions pretending to be IT.
- Make sure every person redeems the complimentary Families account with a personal email. Work logins stay in Business. Personal logins move out.
- MFA on every vault user before you migrate anything that matters.
- Move the ten company logins that would ruin a week: banking, Microsoft 365 / Google admin, DNS/registrar, payroll, PSA/RMM, firewall.
- Shared vaults for shared systems. Least privilege still applies to passwords.
- Rotate anything that lived in the old spreadsheet after import.
- Same-day removal when someone leaves — Business access, not just email. Their Families account is theirs; it is not the offboarding problem if you never put company secrets in it.
If you need the collection design, use the team vault tutorial. If stronger sign-in is next, start with phishing-resistant MFA for high-impact accounts. A password manager does not replace phishing-resistant MFA.
Honest caveats
- It costs money if you are buying it yourself. The Business seat’s included Families membership is how a lot of households end up with a real vault without a second invoice.
- You can lock yourself out. Secret Key plus account password plus a lost Emergency Kit is a bad day. Print the kit. For work break-glass, do not store the only copy inside the same Microsoft 365 tenant.
- You still have to separate items. The included personal account only helps if you use it. Mixing Netflix and the firewall in the company vault is how a departure becomes a mess.
- It is not magic. Watchtower will nag. Someone still has to change the reused password.
- I am not paid by 1Password. If a client already standardized on Bitwarden and runs it like adults, I support that.
Bottom line
Use a real password manager at home and at work. My default is 1Password because people use it, the Secret Key and Travel Mode are grown-up design, and Business (including MSP-provisioned Business) includes an isolated Families account that the company and the MSP cannot read. Work secrets in Business. Personal secrets in Families. Bitwarden is the right answer when budget and admin appetite line up. Browser-saved passwords and a resurrected LastPass tenancy are not.

Michael Narehood