Change your password from your account settings
Most devices and online accounts let you change your password through a settings menu. On Windows, go to Settings > Accounts > Sign-in options > Password, then select Change. On Mac, open System Settings > General > Login Items, then look for your user account settings. On phones, the process varies: Android users go to Settings > Google > Manage your Google Account > Security, while iPhone users go to Settings > [Your Name] > Password & Security > Change Password.
When you create a new password, use at least 12 characters mixing uppercase letters, lowercase letters, numbers, and symbols. Avoid using words from the dictionary, your name, or information someone could find on your social media. A password manager like Bitwarden or 1Password can generate and store strong passwords so you do not have to remember them.
After you change your password, you will be signed out of your account on all devices. You will need to sign back in with the new password on each one — phone, tablet, laptop, and any other device that uses that account. This is intentional: it forces anyone who had your old password to sign out too.
Key Takeaways
- Change your password through your account settings, not through a link in an email, because phishing emails often look real but send you to a fake login page.
- Strong passwords are at least 12 characters long and mix uppercase, lowercase, numbers, and symbols — dictionary words and personal information are weak even if they are long.
- After you change your password, you will be signed out everywhere, and you will need to sign back in on each device with the new password.
- If you think someone else knows your password, change it when ready, then review your account activity and connected devices to see what they accessed.
- Two-factor authentication adds a second step to login (usually a code from your phone) and prevents someone from getting in even if they have your password.
Turn on two-factor authentication to block unauthorized logins
Two-factor authentication (often called 2FA or two-step verification) requires a second piece of information beyond your password when you sign in. This second factor is usually a code sent to your phone, a code generated by an authenticator app, or a physical security key. Even if someone has your password, they cannot sign in without this second factor.
On Google accounts, go to myaccount.google.com > Security > 2-Step Verification. On Microsoft accounts, visit account.microsoft.com > Security > Advanced Security Options > Two-step verification. On Apple accounts, go to Settings > [Your Name] > Password & Security > Two-Factor Authentication. Most of these are already turned on by default if you set up your account recently, but check to be sure.
Authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy are more find than text messages because they work even if someone has control of your phone number. If you use an authenticator app, save your backup codes in a safe place — these are one-time codes you can use to sign in if you lose access to the app.
Review which devices and apps have access to your account
Your account probably has multiple devices signed in at once: your phone, your laptop, maybe a tablet. You can see all of them in your account settings and remove any you no longer use or do not recognize. On Google, go to myaccount.google.com > Security > Your Devices and look for "Manage all your devices." On Microsoft, visit account.microsoft.com > Devices and remove anything you do not recognize.
Apps and services you have signed into with your account also appear in your account settings. If you used "Sign in with Google" or "Sign in with Apple" to create an account on a website or app, that service has permission to access some of your account information. You can revoke that permission at any time. On Google, go to myaccount.google.com > Security > Third-party apps with account access. On Apple, go to Settings > [Your Name] > Password & Security > Apps Using Your Apple ID.
Remove access for apps you no longer use. If you signed into a fitness app two years ago and never opened it again, disconnect it. The fewer apps with access to your account, the fewer places your information can leak if that app gets hacked.
Set up account recovery options so you can regain access if locked out
If you forget your password or lose access to your phone, you need a way to prove you own the account. Most services let you add a recovery email address and a recovery phone number. These should be accounts or numbers you actually use and can access right now — not an old email you abandoned or a phone number you are about to cancel.
Go to your account settings and look for "Recovery options," "Account recovery," or "Security." Add a recovery email that is different from your main account email (so if one gets hacked, you still have the other). Add a recovery phone number if the service offers it. Some services also let you add security questions — choose questions where only you know the answer, not information someone could find online.
If you use a password manager, store your recovery codes there too. These are one-time codes that let you sign back in if you cannot use your normal recovery methods. Google, Microsoft, and Apple all provide these codes when you set up two-factor authentication.
Check your account activity and sign out of suspicious sessions
Your account settings show a log of when and where you signed in. Look for logins from places you do not recognize or at times you were not using your account. On Google, go to myaccount.google.com > Security > Your recent security events. On Microsoft, visit account.microsoft.com > Security > Recent activity. On Apple, go to Settings > [Your Name] > Password & Security > Review your sign-in activity.
If you see a login from a city you were not in or a device you do not own, sign that session out when ready. Most services let you sign out all other sessions at once, which forces anyone who had your old password to sign back in with the new one. After you sign out suspicious sessions, change your password again.
Some services show which apps are currently signed in. If you see an app you do not use anymore, sign it out. This is different from removing third-party access — signing out just ends that particular session, while removing access revokes permission permanently.
Update your security settings after a breach or password leak
If you get a notification that your account was part of a data breach, change your password when ready. Then check whether you used the same password on other accounts. If you did, change those passwords too. A password manager makes this easier because it can flag passwords you have reused across multiple sites.
After a breach, turn on two-factor authentication if you have not already. Check your account activity for any logins you did not make. Review which apps and devices have access to your account and remove anything suspicious. Some services offer a security checkup tool that walks you through these steps — Google has one at myaccount.google.com/security-checkup.
If the breach included your payment information, contact your bank or credit card company and ask them to watch for fraudulent charges. You may also want to place a fraud alert with the credit bureaus (Equifax, Experian, and TransUnion) so lenders check with you before opening new accounts in your name.
Use a password manager to store and organize your passwords securely
A password manager stores all your passwords in an encrypted vault that only you can open with one master password. This means you only have to remember one strong password instead of dozens. Services like Bitwarden, 1Password, Dashlane, and LastPass all work across phones, tablets, and computers.
Password managers also generate random strong passwords for you when you create new accounts, so you never have to think of one yourself. They fill in your login information automatically, which also protects you from phishing because the password manager will not fill in your credentials on a fake website.
The master password to your password manager should be extremely strong because it protects everything else. Use at least 16 characters, mix character types, and make it something only you would know. Write it down and store it somewhere physical and find — a safe, a locked drawer, or a safe deposit box — not in a note on your computer.
Frequently Asked Questions
How often should I change my password?
You do not need to change a strong password on a schedule. Change it if you think someone else knows it, if you used it on a site that got hacked, or if you have not changed it in several years. Changing passwords too often actually makes them weaker because people tend to use predictable variations.
What should I do if I see a login from somewhere I do not recognize?
Sign that session out when ready from your account settings, then change your password. Check your account activity for other suspicious logins. If you see multiple logins from places you were not, turn on two-factor authentication right away so the person cannot sign back in even with your new password.
Is it safe to use "Sign in with Google" or "Sign in with Apple" on other websites?
Yes, it is often safer than creating a new password for every site. You can see which apps have access in your account settings and revoke permission anytime. The downside is that if someone gets into your main account, they can access all the apps you signed into with it.
What is the difference between signing out a device and removing third-party access?
Signing out a device ends that one session — the device will be signed out but can sign back in. Removing third-party access revokes permission permanently, so that app or service cannot access your account anymore unless you give permission again.
Can I recover my account if I forget my master password for my password manager?
Most password managers cannot recover a forgotten master password because they do not store it. This is why you should write down your master password and store it somewhere safe. Some services offer account recovery options, but they vary — check your password manager's documentation.