How to Check Active Account Sessions and Sign Out Old Devices
Review unfamiliar logins, understand device-session lists and remove access from old computers without mistaking sync activity for an intrusion.
An old laptop can remain signed in long after you stop using it. So can a browser at a relative's house or a phone you handed down. Reviewing account sessions is a useful maintenance job because it deals with access that already exists, not just the password used to create it.
The list can look more alarming than it really is. One device may appear several times, and a recent timestamp does not necessarily mean someone sat down and read your messages. Start by understanding what the service is showing, then remove access you no longer need.
Open the account yourself
Use the service's app, a saved bookmark or an address you enter directly. A security alert can be genuine, but you do not need to use its embedded login link to investigate it. Open the account independently and look for Security, Your devices, Sessions or Login activity.
Begin with primary email and your main cloud account. These often connect to other services or hold the files you most want to protect. A social account can follow, especially if it has publishing or business permissions.
Make sure you are reviewing the correct account. When several family or work identities are open in one browser, it is easy to change settings for the wrong one. A clearly labelled browser profile helps prevent that mistake.
Read the list as evidence, not a verdict
Google's device-session guide explains that multiple sessions can belong to the same device. It also notes that timestamps may reflect background communication and locations can be approximate. That is a useful example of why a session list needs interpretation.
For each entry, compare several details: device type, browser, rough location, last activity and whether you recently reset or replaced a device. A new browser installation may create a new entry even though the laptop is familiar.
A VPN or mobile network can also make location clues less intuitive. Do not treat a city label alone as proof that someone else has your account. Equally, a familiar city does not prove the activity is yours.
When the interface provides a detailed event history, read it before deciding. Password changes, new recovery methods or actions you did not authorize are more meaningful than a slightly surprising place name.
Remove devices you know you no longer use
Start with easy decisions: the computer you sold, a borrowed browser, an old phone and a session created for a one-off task. Select the service's sign-out or remove-session control and read its confirmation message.
Do not assume the action erases files already downloaded to that device. Remote sign-out deals with account access as supported by the provider. It is not a substitute for wiping a device before selling it.
Keep one trusted current session available while you work. If you choose a sign-out-everywhere option, be prepared to authenticate again on legitimate devices. Have your second factor and recovery material ready first.
For Google, sign out of all matching sessions when you cannot distinguish whether similarly named entries refer to one old device or several. Other services may group devices differently, so follow their specific interface rather than looking for an identical button.
Investigate activity you genuinely cannot explain
Pause and write down the details visible in the account's own history. A screenshot can help retain event times, but remove private identifiers before sharing it with someone assisting you. Our screenshot privacy guide covers that preparation.
From a trusted, updated device, follow the provider's compromised-account procedure. Google's recovery and security guide is one example. It includes reviewing activity and securing the account, not merely dismissing an alert.
Change a password when it may be compromised, replace reused versions on other accounts and review authentication methods. Check that recovery addresses and phone numbers are still yours. For email, also inspect forwarding, filters and delegation because those can create access paths outside the obvious device list.
If the affected account belongs to an employer or school, report the event through its security process before deleting useful evidence or changing organization-controlled settings.
Review connected apps separately
A calendar service, photo editor or automation may have permission to access account data without appearing as an ordinary browser login. The session list is therefore only one part of the review.
Open the account's connected-apps page and inspect permissions you no longer use. Google's linked-app documentation distinguishes sign-in links from permission to access account data. Removing one type of connection should not be assumed to remove every other relationship with the same app.
Our guide to reviewing connected apps walks through the practical decisions. Check an alternative login before disconnecting a service you still need, and remember that revocation does not automatically delete data previously copied by that service.
Do not use password changes as the only clean-up step
Providers differ in how they treat existing sessions after a password change. Some access may end, while exceptions or connected services can require additional action. Read the confirmation and use the explicit session controls when available.
Review app passwords, security keys, passkeys and trusted-device settings as separate items. These are different ways of authenticating or maintaining access. Deleting a passkey does not necessarily delete the account itself, and uninstalling an app does not necessarily revoke its server-side permission.
Keep the job focused. You are looking for access that is unnecessary, unexplained or no longer under your control. You do not need to repeatedly sign out every familiar device just to make the list look tidy.
Make it part of changes you already remember
Review sessions after selling a device, finishing a trip that involved borrowed equipment, leaving a job or noticing a meaningful security alert. A periodic check can also fit into a personal privacy plan.
Record the decision, not every technical detail: old tablet signed out, unfamiliar browser investigated, recovery address confirmed. Keep notes private and avoid storing copies of full session tokens or other sensitive diagnostic data.
Finish by testing that your current devices still work and that any removed device is shown as signed out where the service provides that status. A shorter session list is nice. Knowing why each remaining connection belongs there is the real benefit.
Sources and further reading
- Google: Review devices and sessions Consulted 28 September 2026.
- Google: Secure a compromised account Consulted 28 September 2026.
- Google: Manage connected apps Consulted 28 September 2026.
Consult the linked documentation for current details. Settings, availability and interface labels may change.
Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.