The first time I spotted an unfamiliar sign-in on my Google account, it was a browser session from a city three hours away that I had never visited. My password still worked, nothing looked broken, and that was exactly the problem — an unknown login does not always announce itself. The real danger is the session that stays quietly open, watching your inbox while everything appears perfectly normal.
You do not need special software to fix this. A few clicks on each platform’s security page gives you a clear list of every device, browser, and location with an open session on your account. I now run this check on the first of every month, and catching a stale session from a phone I sold last year matters just as much as catching a stranger.
Quick Answer
Open myaccount.google.com/security, scroll to “Your devices,” and click “Manage all devices” to review and sign out Google sessions. For Microsoft, visit account.microsoft.com/security and check “Sign-in activity.” For Apple, open Settings then [Your Name] on iPhone, or visit appleid.apple.com to see and remove connected devices.
Why should you check for unknown logins at all?
Because a leaked password rarely triggers an obvious lockout. When my credentials turned up in a breach years ago, the attacker did not change my password — they simply logged in and lurked, reading password-reset emails for my other accounts. Reviewing active sessions is the one check that exposes that quiet access, and it works even when every other sign looks fine.
Running it monthly also clears out forgotten devices. An old laptop you recycled or a phone you handed to a relative often stays logged in for years, and each one is a door you forgot to close.
Checking active sessions reveals quiet intruders and forgotten devices that a password change alone would never catch.
How do you check active logins on Google?
Step 1: Open the security page
Go to myaccount.google.com/security. Sign in if prompted, then scroll down to the “Your devices” section.
Step 2: Review active sessions
Click “Manage all devices.” You will see every phone, tablet, and browser that has accessed your Google account recently, along with its approximate location and last-activity time. A session from a city you have never visited, or a device you no longer own, is a red flag.
Step 3: Sign out the device
Click the suspicious device, then click “Sign out.” Google signs that device out of all Google services immediately. The person on that device would need your password to get back in, which is exactly why you should change it right after.
Pro tip: Once I sign out an unknown device, I change my Google password and confirm two-factor authentication is on before doing anything else. That locks the door before a removed user can try to slip back in.
Google gives you a per-device list and instant remote sign-out, making it the easiest of the three to clean up.
How do you review sign-in activity on Microsoft?
Step 1: Open sign-in activity
Go to account.microsoft.com/security and sign in. Click “View my activity” under the Sign-in activity section.
Step 2: Read the activity log
Microsoft shows every sign-in by date, device, browser, IP address, and approximate location. I scan for logins from countries I have not visited, or odd timestamps like 3 a.m. when I was asleep.
Step 3: Respond to suspicious logins
Each entry has a “This wasn’t me” button that launches a guided security review and password reset, which forces all active sessions to sign out. If you spot a currently active session you do not recognize, change your password immediately to cut off access.
Troubleshooting tip: If you see repeated logins from one unfamiliar IP, your credentials may have leaked. Check your email at Have I Been Pwned (free, no sign-up), then read this breach-check guide for the next steps.
Microsoft shows a detailed sign-in log rather than per-device toggles, so a password reset is how you force a stranger out.
How do you remove devices from your Apple account?
Step 1: Find your devices
On iPhone or iPad, go to Settings then [Your Name] and scroll to the device list. On Mac, open System Settings then [Your Name] and scroll down. On the web, sign in at appleid.apple.com and click “Devices” in the sidebar.
Step 2: Review each device
Tap or click any device to see its model, operating system version, and serial number. A device you sold, gifted, or lost should not still appear here.
Step 3: Remove the device
Tap “Remove from Account” and confirm. The device instantly loses access to iCloud, Apple Pay, and your iCloud data. Apple also sends a security notification email to your registered address.
Apple’s device list, like Google’s, lets you remove unrecognized hardware instantly and notifies you by email when you do.
Which platform makes removal easiest?
When I cleaned up all three accounts in one sitting, the differences were obvious: Google and Apple let me kill a specific device in one click, while Microsoft routes you through a password reset. The table below sums up where to look and what each platform actually lets you do.
| Platform | Where to check | Per-device session view? | Remote sign-out? |
|---|---|---|---|
| myaccount.google.com/security | Yes | Yes, instantly | |
| Microsoft | account.microsoft.com/security | Sign-in log only | Via password reset |
| Apple | appleid.apple.com / Settings | Yes | Yes, instantly |
Google and Apple offer instant per-device sign-out, while Microsoft relies on a password reset to evict an intruder.
Common Mistakes to Avoid
- Checking only one account. Most people secure Google but forget Microsoft and Apple, and attackers count on that. The fix: review all three in the same sitting.
- Removing a session but not changing your password. Signing out kills the active session, but anyone who still has your password can sign back in within minutes. The fix: change the password immediately after removing an unknown device.
- Dismissing nearby but unfamiliar locations. VPNs and mobile towers can make your own logins look like they came from another city. The fix: compare the timestamp to your own activity before deciding, and investigate anything you cannot explain.
- Leaving old devices on your account. A phone you sold two years ago and never signed out is still a live session. The fix: remove every device you no longer own.
- Skipping two-factor authentication after cleanup. Evicting an intruder without enabling 2FA is like changing the lock but leaving a spare key under the mat. The fix: pair this check with a strong password manager and 2FA.
Frequently Asked Questions
Does removing a device delete my files?
No. Signing a device out only revokes its access to your account. When I removed an old iPad from my Apple ID, every photo and document in iCloud stayed exactly where it was on the server.
Will the person on the removed device know they were signed out?
Not directly. They simply find themselves logged out the next time they open a linked app. A friend I removed from my old Netflix-linked Google session just saw a “please sign in again” prompt with no alert naming me.
How often should I check my active sessions?
Once a month is plenty for most people. I run mine on the first of the month, and I always check immediately after using a public computer, as I did at a hotel business center last spring.
What if I cannot sign in because someone already changed my password?
Use the “Forgot password” recovery flow on each platform. When a relative’s account was hijacked, Google’s trusted-phone recovery got her back in within ten minutes, even after the attacker had reset the password.
Is it safe to run this check on a public computer?
Yes, if you sign out fully and clear saved passwords before walking away. I once forgot to clear a library PC and had to remotely sign that very session out from my phone, which is the better tool for the job anyway.
Conclusion
Five minutes on each platform’s security page can close access you never knew was open. Run the check on Google, Microsoft, and Apple today, remove anything unfamiliar, and reset your password the moment something looks off. Make it a monthly habit, pair it with strong unique passwords and 2FA, and start with Google right now.