How to See Every Device Signed Into Your Account
Short answer
Each provider keeps a live device list in account settings under Security or Sign-in: myaccount.google.com/device-activity for Google, Settings → your name on an Apple device, account.microsoft.com/devices for Microsoft. Signing a device out revokes its session immediately and deletes nothing. Check connected apps too, because those tokens survive a password change.
On this page
Two situations bring people to this page: an email saying there was a new sign-in, or the sudden realisation that a laptop sold three years ago might still be reading your mail. Both are answered in the same place, and both are usually less dramatic than they feel.
Every major provider keeps a live list of sessions holding valid access to your account. You can read it in a couple of minutes and revoke anything from your phone without touching the device itself.
Where each list lives
The menus move between versions, so these are described functionally with the direct links where they are stable.
Google. Go to myaccount.google.com/device-activity, or open
myaccount.google.com → Security → Your devices → Manage all
devices. Each entry gives a device name, a location, and the last activity
time. The full walkthrough for Google accounts
covers the adjacent settings in more detail.
Apple. On any signed-in device, open Settings (or System Settings on a
Mac) → your name, and scroll past your details to the device list at the
bottom. Tapping a device shows its model, serial number and whether it is a
trusted device for verification codes. You can also reach it at account.apple.com
in a browser.
Microsoft. Go to account.microsoft.com/devices for registered devices, and
check Security → Sign-in activity for the record of recent sign-in
attempts. Microsoft splits these more than the others do, so look at both.
Most other services bury an equivalent under Settings → Security → something like “Active sessions”, “Where you’re logged in” or “Devices”. Facebook, Instagram, WhatsApp, Netflix, Spotify and Dropbox all have one.
Reading the list without overreacting
Most unfamiliar entries are ordinary. Check yours against this before treating anything as an intrusion.
| What you see | Usually means | Action |
|---|---|---|
| A city 50–150 miles away | Your provider’s routing hub | None |
| A generic name like “Linux” or “Windows” | A TV, console or older device | Identify, then sign out |
| The same laptop three times | Separate browser and app sessions | None |
| A device you sold or gave away | A session that survived the handover | Sign out |
| A country you have no link to | Possible compromise, or your VPN | Investigate |
| Activity while you were asleep | Background sync, or a real intrusion | Investigate |
The last two rows are the ones that matter. Everything above them sends people into unnecessary password resets, and the location estimate in particular is responsible for most false alarms, because IP geolocation is approximate by nature, and mobile data is worse than broadband.
A single unfamiliar signal is weak evidence. A combination is strong: an unknown device and a recovery phone number you did not add, or an unknown sign-in and a new email forwarding rule. Look for the pattern rather than the single row.
Sign out, then check what survived
Signing out is immediate and non-destructive. Click the device, choose Sign out or Remove, and the session token is revoked. The device shows a login screen next time it tries to sync, and nothing stored locally is deleted.
If something genuinely looks wrong, do the rest in this order. Order matters, because a password change made too early tips off an intruder while leaving their other access intact.
- Change the password, from a device you trust, to something long and unique.
- Check recovery options. A changed recovery email or phone number is the classic persistence trick, because it lets someone back in later regardless of your new password. Fix any you did not set.
- Revoke app-specific passwords. Google’s are the common example: 16-character codes generated for older software, valid indefinitely, and never challenged for a second factor. They are unaffected by a password change.
- Review third-party app access. Years of granting sites permission to read your contacts, calendar or files leaves tokens that also survive a password change. Remove anything you do not actively use, starting with anything holding full mailbox or file-write permission.
- Check email rules and forwarding. An auto-forward rule quietly copying your mail elsewhere is a known pattern and invisible unless you look.
- Re-read the device list, because the password change will have cleared some sessions and left others.
- Turn on a stronger second factor if you have not. Which type of two-factor authentication is safest covers the ranking.
Steps three and four are the ones almost everyone skips, and they are where persistent access actually hides.
Devices you no longer have
Selling or recycling a phone or laptop without signing it out is extremely common, and the session can outlive the handover by years.
Sign the device out from the list, then on Apple and Google specifically use the Remove from account option where offered, which also clears the activation lock association. For a phone you genuinely lost rather than sold, use Find My Device or Find My iPhone to lock or erase it — signing out of the account does nothing about the photos and documents already stored on the handset.
If you cannot identify a device at all, sign it out anyway. The cost of being wrong is signing back in on something you own.
What a device list will not tell you
Worth being clear about the gaps, because the list looks more comprehensive than it is.
- Session cookies stolen by malware can resume an authenticated session without a new sign-in appearing. The list shows the original session, which looks entirely legitimate.
- Anyone reading a device you are signed into generates no entry. Physical access to an unlocked laptop leaves no trace here.
- Older sessions on minor services often are not tracked at all.
- The location is an estimate, and a deliberate one. Do not plan around it.
This is why the useful outcome of the exercise is rarely catching an intruder. It is noticing that 2FA was never switched on, or that an app you stopped using years ago still has full access to your mailbox.
Realistic expectations
A typical list contains a forgotten browser, an old tablet, a smart TV with a generic name, and a location that looks wrong because IP lookup is imprecise. Clearing the ones you no longer use takes five minutes and is hygiene rather than an emergency.
Do it after selling a device, after a sign-in alert you cannot explain, and once or twice a year otherwise. If you find something genuinely unexpected, work through the seven steps above rather than only changing the password — a new password with an attacker’s recovery email still attached has solved nothing.