ACTIVE SESSIONS & DEVICES: WHO IS SIGNED IN?
An account can remain signed in on several phones, computers, browsers or applications.
That convenience creates an important security question:
DO YOU KNOW WHICH DEVICES AND SESSIONS STILL HAVE ACCESS TO YOUR ACCOUNT?
Account security is not only about the password you remember. It also includes the access that remains active after authentication.
1. WHAT IS AN ACTIVE SESSION?
An active session represents an authenticated connection between an account and a device, browser or application.
You may have sessions on:
- Your phone
- Your personal computer
- A work computer
- A tablet
- A browser
- A mobile application
Services may display sessions differently. Some show devices, browsers, locations or recent activity.
2. WHY SESSIONS MATTER
Imagine signing in on a borrowed computer and forgetting to sign out.
The account may remain accessible from that device.
Similarly, if an attacker successfully signs in, an active session may remain relevant depending on how the service manages sessions and credential changes.
Session management therefore deserves attention.
3. REVIEW DEVICES AND SESSIONS
For important accounts, open the official security settings and look for:
- Devices
- Active sessions
- Recent sign-ins
- Trusted devices
- Login history
- Browsers
Ask:
“Do I recognise this?” “Do I still use this device?” “Does the timing make sense?”
4. AN UNFAMILIAR DEVICE IS A SIGNAL, NOT AUTOMATIC PROOF
An unfamiliar device does not always mean an attacker.
You may have forgotten an old device, changed browsers or used a network that produced an unusual location.
But an unexplained device deserves verification.
5. LOOK AT MULTIPLE SIGNALS
When reviewing an unfamiliar session, consider:
- Device type
- Browser
- Time
- Activity
- Approximate location
- Whether you initiated the login
Do not rely only on location because network routing can produce inaccurate or unexpected locations.
6. SIGN OUT OF DEVICES YOU NO LONGER TRUST
If a service provides remote sign-out or device removal, use it when appropriate.
This can be useful when:
- A phone is lost or stolen.
- A computer was sold.
- A device was given away.
- You used a shared computer.
- An unfamiliar session appears.
7. LOST OR STOLEN PHONES
A lost phone can provide access to more than calls and messages.
Depending on the device, it may provide access to:
- Social media
- Banking applications
- Password managers
- Authenticator applications
- Cloud storage
- Messaging services
Consider:
- Locking the device remotely.
- Locating it if appropriate.
- Contacting the mobile network provider where necessary.
- Reviewing important account sessions.
- Removing the lost device from accounts where appropriate.
- Securing important accounts.
8. SHARED AND PUBLIC COMPUTERS
If you sign in on a shared computer:
- Sign out when finished.
- Avoid saving passwords.
- Do not leave the browser signed in.
- Avoid marking the device as trusted unless appropriate.
- Review sessions later if you are uncertain.
Convenience should not become permanent access for the next person.
9. RECENT LOGIN ACTIVITY
Login history can help you understand how and when access occurred.
Consider the complete event rather than one field.
A strange location combined with an unfamiliar device and an unexpected time may be more significant than an unusual location by itself.
10. WHAT IF YOU FIND AN UNFAMILIAR SESSION?
Do not panic.
First verify through the official service.
If you cannot explain the session:
- Sign it out or remove it where supported.
- Change the password if compromise is possible.
- Review MFA.
- Review recovery methods.
- Review connected applications.
- Check security notifications.
- Look for other unfamiliar sessions.
11. PASSWORD CHANGES AND SESSION REVOCATION
Changing a password can be important after suspected compromise.
But do not assume every service handles existing sessions in the same way.
After a suspected compromise, review and revoke sessions through the service's official controls where available.
A useful sequence is:
CHANGE → REVOKE → REVIEW → SECURE
12. TRUSTED DEVICES
Some services allow devices to be marked as trusted so that future authentication is easier.
Review trusted devices periodically.
Remove devices you no longer control or no longer need to trust.
13. DEVICES YOU SOLD OR GAVE AWAY
Before transferring a phone or computer:
- Sign out of important accounts.
- Remove the device from account settings where appropriate.
- Back up what you legitimately need.
- Use the device's secure reset process where appropriate.
- Confirm that important accounts no longer list it as trusted.
14. SESSIONS AFTER A COMPROMISE
If an account may have been compromised, do not stop at the password.
Review:
- Active sessions
- Devices
- MFA
- Recovery email
- Recovery phone
- Connected applications
- API keys or app passwords where relevant
- Email forwarding and filters
- Security notifications
The goal is to remove unauthorised pathways, not merely change one credential.
15. EMAIL DESERVES SPECIAL ATTENTION
If your email account is compromised, an attacker may be able to observe password resets and sensitive notifications.
After recovering an email account, inspect sessions and devices as well as forwarding, filters and connected applications.
16. FINANCIAL AND CRYPTO ACCOUNTS
For accounts involving money or digital assets, unfamiliar access should be treated seriously.
Review:
- Recent logins
- Devices
- Sessions
- Transactions
- Security settings
- Connected applications
- Recovery methods
For cryptocurrency wallets, remember that wallet control may depend on keys or recovery phrases rather than a normal account session.
NEVER GIVE A WALLET RECOVERY PHRASE TO SOMEONE WHO CLAIMS THEY NEED IT TO REMOVE AN UNFAMILIAR SESSION OR SECURE A WALLET.
17. HOW OFTEN SHOULD YOU REVIEW SESSIONS?
There is no single schedule for every service.
A practical approach is to review important accounts periodically and whenever something unusual happens.
Review promptly after:
- Losing a device
- Selling or replacing a device
- Suspecting compromise
- Receiving an unexpected login alert
- Using an unfamiliar computer
- Changing important security settings
18. COMMON MISTAKES
Mistake 1: “I do not recognise the device, but I will ignore it.”
Why this is dangerous: It may represent continued unauthorised access.
Mistake 2: “I changed my password, so I do not need to check sessions.”
Why this is dangerous: Session handling differs by service and should be reviewed separately.
Mistake 3: “I sold the phone months ago, so it cannot matter.”
Why this is dangerous: It may still be listed as trusted or signed in.
Mistake 4: “The location looks strange, so it must be an attacker.”
Why this is dangerous: Location data can be imprecise.
Mistake 5: “I will message the unfamiliar user to ask who they are.”
Why this is dangerous: Do not engage an unknown person as your method of verifying account activity. Use the official service controls.
19. HOW TO RESPOND TO A POSSIBLE ACCOUNT TAKEOVER
If you believe someone accessed an important account:
- Use a trusted device.
- Open the official service.
- Change the password if appropriate.
- Revoke unfamiliar sessions.
- Review MFA.
- Review recovery methods.
- Review connected applications.
- Check security notifications.
- Check important account activity.
- Preserve useful evidence where appropriate.
20. STEP-BY-STEP: REVIEW AND TERMINATE ACTIVE SESSIONS
Use this general process when reviewing an important account. Menu names vary by service, so use the official app or website and look for Security, Privacy & Security, Devices, Active Sessions, Recent Sign-ins or Login Activity.
STEP 1 — OPEN THE OFFICIAL SERVICE
Open the account through the official app or by entering the official website yourself. Do not use a security link supplied in an unexpected message.
STEP 2 — OPEN SECURITY SETTINGS
Go to the account's Security, Privacy & Security, Account or equivalent settings area.
STEP 3 — FIND DEVICES OR ACTIVE SESSIONS
Look for Devices, Where You're Signed In, Active Sessions, Login Activity, Recent Sign-ins, Trusted Devices or similar.
STEP 4 — REVIEW EACH SESSION
Check the device, browser or application, approximate location, date or time and any other activity information the service provides. Consider the signals together rather than relying on location alone.
STEP 5 — IDENTIFY SESSIONS YOU NO LONGER NEED
Look for old phones, sold or shared computers, forgotten browsers and devices you no longer control.
STEP 6 — TERMINATE THE SESSION
For a session you no longer trust or need, use the service's official Sign out, Log out, Remove device, Revoke or equivalent control. If the service offers remote sign-out, follow its official process.
STEP 7 — IF A SESSION MAY BE UNAUTHORISED
Do not contact the person behind the session. Secure the account through the official service instead. Change the password where appropriate, review MFA and recovery methods, review connected applications and check for other unfamiliar sessions.
STEP 8 — VERIFY THE RESULT
Return to the sessions or devices list and confirm that the unwanted session is no longer active or listed as expected.
STEP 9 — PRESERVE USEFUL EVIDENCE
If compromise is suspected, record relevant dates, devices, notifications and other useful details before they disappear, where safe and appropriate.
21. YOUR ACTIVE-SESSIONS CHECKLIST
□ Do I know which devices are signed in? □ Have I removed old devices? □ Have I reviewed trusted devices? □ Do I recognise my active sessions? □ Do I know how to sign out a device remotely? □ Would I act quickly if my phone were lost? □ After suspected compromise, would I review sessions as well as passwords? □ Have I reviewed connected applications? □ Do I know the official support channel?
22. A PRACTICAL EXAMPLE
You receive a new-login notification at 2:00 a.m.
You were asleep.
You open the official application and find an unfamiliar browser session.
Instead of contacting the person behind the activity, you:
- Remove the unfamiliar session.
- Change the password if appropriate.
- Review MFA.
- Review recovery information.
- Review connected applications.
- Check other sessions.
- Preserve useful evidence.
This turns an unexplained event into a controlled security response.
23. IF YOU REMEMBER ONLY ONE THING
An account is not protected only by the password you remember.
It is also affected by the devices, sessions, applications and recovery methods that remain connected to it.
Know what is signed in. Remove what you no longer trust. Review after unusual activity.
