How to Lock Down Your Google, Apple, or Microsoft Account
Your platform account ties together your email, photos, files, payments, and devices. This guide shows beginners the exact settings to harden on Google, Apple, and Microsoft so one login cannot be turned against you.

Table of contents
A Google, Apple, or Microsoft account is not one account — it is the hub that quietly connects almost everything on your devices. It holds your email, your photos, your saved files, your app purchases, and often a payment method. It is also what unlocks a new phone or laptop when you sign in. Because so much hangs off it, this single login deserves your strongest protection.
The specific menus differ between the three, but the principles are identical. Below is a checklist you can work through for whichever platform you use most. It takes about fifteen minutes per account and you only do it once.
Start with the built-in security checkup
Each provider offers a guided review tool that walks you through the most important settings in one place:
- Google has a Security Checkup in your account settings.
- Apple groups security under your Apple Account and Sign-In settings.
- Microsoft has a Security dashboard in your account.
Run whichever one applies. It will flag missing protections, unfamiliar devices, and old recovery details. Doing this first gives you a map of what still needs attention.
Add a strong second step
A password by itself is a single point of failure. Turn on multi-factor authentication (often called two-step or two-factor verification) so a stolen password is not enough to get in.
Not all second factors are equal. If you are unsure which to pick, what is multi-factor authentication and which type is safest breaks down the options in plain language. As a rule of thumb: an authenticator app or a hardware/passkey option is stronger than a text-message code, because SMS can be intercepted or redirected.
Even better, consider a passkey. A passkey replaces the password entirely with something tied to your device and unlocked by your fingerprint, face, or PIN. Google, Apple, and Microsoft all support them now. If the term is new to you, passkeys explained for beginners covers what they are and why they resist phishing, and how to set up passkeys on iPhone, Android, Windows, and Mac shows the actual steps.
Fix your recovery options
Account recovery is the emergency back door — and if it is neglected, it is also an attacker's shortcut. Check three things:
- Recovery email and phone. Confirm they are current and belong to you. Remove anything outdated.
- Recovery or backup codes. Generate them, then store them offline — printed and put somewhere safe, not saved on the same device you are trying to protect.
- Trusted contacts or account recovery contacts. Apple in particular lets you nominate a trusted person; make sure it is someone you actually trust.
A recovery email is only as strong as its own protection, so make sure that account has MFA too. Otherwise you have simply moved the weak point one step sideways.
Review your devices and sessions
Every place you have signed in stays remembered until you remove it. In the account's device or session list, look for anything you do not recognise — an old phone you sold, a computer you no longer use, or a device in a location that makes no sense. Sign those out. This closes off access you forgot you had granted.
Prune connected apps and permissions
"Sign in with Google," "Sign in with Apple," and "Sign in with Microsoft" are convenient, but each one is a standing connection to your account. So are third-party apps you granted access to your calendar, contacts, or files.
Open the connected-apps or app-permissions section and remove anything you do not use or recognise. Be especially wary of anything with broad access to your email or files. Fewer connections means a smaller attack surface.
Turn on the alerts
Make sure security notifications are switched on so you hear about new sign-ins, password changes, and recovery changes as they happen. When one of these lands unexpectedly, it is your early warning. Do not click links inside such an email, though — open the app or type the website address yourself, because fake "security alerts" are a classic phishing tactic.
Check whether you have already been exposed
Before you call it done, it is worth knowing whether your credentials are already floating around from an old breach. How to check whether your password has been leaked without making things worse explains how to do this safely. If something turns up, change that password immediately and confirm MFA is on.
Platform-specific extras worth enabling
A few high-value options that are easy to miss:
- Google offers Advanced Protection for people who want the strictest settings, which enforces passkeys or hardware keys.
- Apple offers Advanced Data Protection, which extends end-to-end encryption to more of your iCloud data, and a Recovery Key for account recovery.
- Microsoft lets you go fully passwordless, removing the password from the account entirely once passkeys or the authenticator app are set up.
You do not need every advanced feature. The core four — a strong unique password or passkey, MFA, clean recovery options, and a tidy device list — already put you ahead of the vast majority of accounts attackers find easy to break. Do those, then revisit the settings once or twice a year to keep them current.


