Account security

Does Changing Your Password Log Out Other Devices? Google and Microsoft Explained

Check what password changes do to Google and Microsoft sessions, then review device sign-out, connected-app access, recovery settings, and remaining activity.

Changing a password does not provide a universal guarantee that every device, application, and delegated connection loses access immediately. For a personal Google or Microsoft account, check the provider's sign-out controls and connected applications as well as changing the password.

If you suspect unauthorized access, perform recovery from a device you trust and use the provider's official account pages. This guide covers personal accounts; work and school accounts can have administrator-managed session controls. A password change is one part of containment, not the entire process.

Separate four kinds of access

Account containment sequence covering password, signed-in sessions, connected app access, and recovery settings
Review both how someone signs in and which access has already been granted.

On narrow screens, scroll the table horizontally.

Access typeWhat to reviewWhy it is a separate check
PasswordThe secret used for a password-based sign-inReplacing it does not describe every existing session's lifetime
Signed-in sessionA browser, application, or device already using the accountThe provider determines when that session must authenticate again
Connected applicationPermission granted to another serviceDelegated access is not simply another copy of your password
Recovery and sign-in methodsRecovery contacts, trusted methods, and other ways back into the accountRemoving one route is insufficient if an unauthorized route remains

OAuth's token-revocation specification treats revocation as an explicit mechanism and recognizes implementation details such as propagation. It does not specify a universal consumer-account password-reset policy. Check what your provider promises instead of transferring a behavior from another service.

What happens when you change a Google password?

Google documents that changing or resetting the password signs you out broadly, with exceptions. Those include devices used to verify your identity, some devices with third-party applications that have account access, and certain home devices granted access. The December 2025 password-change guidance lists those exceptions.

That means “I changed the password” and “I reviewed every remaining access path” are different statements. After replacing a compromised or reused password, open the account's security area and inspect devices and connections. Do not assume an entry you can still see must represent a currently active attacker.

Review Google's devices and sessions

  1. Open your Google Account through a known bookmark or the provider's own navigation.
  2. Go to Security & sign-in, then Your devices and Manage all devices.
  3. Inspect entries you do not recognize, including their session details.
  4. Sign out of sessions you cannot account for. If several unfamiliar sessions share the same device name, review and sign out of each relevant session rather than assuming they are one entry.

Google's device-access guidance from December 2025 explains that one device can have several sessions, and that recently used devices can remain listed. Times can reflect background communication, not just a person actively opening the account.

Use the signed-out indication and the detailed activity together. A familiar device name is not sufficient proof of ownership, but multiple entries or a recent timestamp are not sufficient proof of compromise either.

Use Microsoft's explicit sign-out-everywhere control

For a personal Microsoft account, open the account security dashboard and its advanced security options. Locate Sign out everywhere and select the sign-out action. This is the documented containment control to inspect rather than assuming that changing the password or removing a device listing has already done the same thing.

Microsoft's March 2026 sign-out guidance allows up to 24 hours and identifies an Xbox-console exception. Handle console sign-out through Microsoft's Xbox instructions when applicable. Do not describe the general control as instant revocation across every product.

Record when you requested sign-out. During the documented interval, continue securing recovery methods and applications. If unauthorized activity continues, use official account-recovery support; do not repeatedly change unrelated settings in the hope of forcing a faster result.

Revoke connected-app access separately

In your Google Account, inspect the third-party connections page and distinguish an application using Sign in with Google from one that has permission to access Google account data. Select the connection, review its details, and remove the access you no longer authorize.

The January 2026 connections documentation describes different connection types and their removal controls. Ending a connection can stop useful features. It also does not necessarily delete information the other service already holds or delete the account you created there.

For other providers, use their own application-permission controls. Do not assume a Google procedure or a Microsoft device list manages every service you once connected. If an application has its own account and recovery settings, review those through that application's official site.

Check how someone could regain access

Review the recovery email address and phone number, enabled sign-in methods, and any unfamiliar security changes. Preserve a recovery method you control before removing an old one, so the containment process does not lock you out. Never approve an unexpected sign-in prompt or disclose a one-time code to someone claiming to help.

If the affected account is your email account, also inspect unfamiliar forwarding and inbox rules. Removing an active session does not explain whether settings were changed while someone had access. Keep a record of suspicious changes before correcting them.

The data breach response checklist covers broader recovery priorities. If a personalized message is steering you into a supposed security check, use the post-breach phishing guide to verify the request through an independent channel.

Verify containment without treating old data as live access

  • Confirm that the password was changed through the genuine provider.
  • Record the explicit session sign-out actions and their times.
  • Check connected apps and recovery settings for anything unauthorized.
  • Review fresh security events after the provider's stated sign-out interval.
  • Distinguish new successful account activity from a device's ability to display previously downloaded email or files.

A remote sign-out is not a remote erase. Information already downloaded to another device may remain there, even after new account access is stopped. Conversely, an old device name remaining on a page does not establish that it can still make authenticated requests.

If you cannot regain control, the recovery process changes unexpectedly, or new unauthorized actions continue, stop relying on the checklist alone and contact official support. For a work or school account, give the administrator the relevant events and times so they can investigate the managed identity system.

FAQ

Does changing my Google password sign out every device?

Google documents exceptions, including some verification devices and third-party or home-device access. Review devices, sessions, and connected applications separately.

How long can Microsoft's sign-out-everywhere action take?

Microsoft states that it can take up to 24 hours and excludes Xbox consoles from that general action.

Does removing app access delete data the app already received?

Not necessarily. Ending access and deleting data held by another service are separate matters. Review that service's account and data controls.