Appearance
How to Run a Personal Security Checkup in 15 Minutes
Applies to: Microsoft 365 (work or school account); Windows 11, Windows 10; Microsoft Edge, Google Chrome
Article Type: How-To
Last Updated: 2026-07-29
Summary
Seven checks, fifteen minutes, one sitting. This checkup walks the places an account problem actually shows up — your sign-in methods, your login history, your mailbox rules, your connected apps, your saved passwords, your recovery details, and your device lock. Each step tells you what a healthy result looks like and links to the full guide if something needs fixing.
Prerequisites
- A Microsoft 365 work or school account.
- Your phone nearby, if the Microsoft Authenticator app is one of your sign-in methods.
- Fifteen uninterrupted minutes. No admin rights are required for any step in this article.
Instructions
Run the steps in order. Each one ends where the next one starts, so you are not hunting for pages twice.
1. Review Your Sign-In Methods (3 minutes)
Start here. This is the highest-value check on the list.
- Open a browser and go to https://mysignins.microsoft.com/security-info.
- Sign in with your work account if prompted. The Security info page opens, listing every method your account can use to prove it is you — Microsoft Authenticator, Phone, Email, Password, and any security keys.
- Read every row and ask one question: do I recognize this device, number, or address? A phone model you have never owned, or a number ending in digits that are not yours, is the finding you came for.
- To remove a method you do not recognize, click Delete on that row and confirm. The row disappears from the list.
- Check the Default sign-in method line near the top of the page. It names the method your account reaches for first — confirm it is the one you actually use.
Why this matters: An attacker who gets into your account once will often register their own phone or authenticator as an extra sign-in method. That gives them a way back in even after you change your password. Deleting it closes the door.
Note: Do not delete a method if it is the only one left, or you lock yourself out. Register a replacement first with Add sign-in method, confirm the new one works, then remove the old one.
Deep dive: How to Use the Microsoft Authenticator App and How to Transfer MFA to a New Phone (Microsoft 365).
2. Check Your Recent Sign-In Activity (2 minutes)
Stay in the same browser tab — the history lives one click away.
- Click My sign-ins in the left navigation pane, or go straight to https://mysignins.microsoft.com. The page lists your recent sign-in events, newest first.
- Read each entry across five fields: date and time, location, device and browser, the app that was used, and whether the attempt succeeded or failed.
- Look for four things — a country you have not been to, a device or browser you do not own, a successful sign-in at an hour you were asleep, and clusters of failed attempts you did not make.
- Click Looks unfamiliar? next to any entry you do not recognize and follow the prompts. This reports the sign-in to your security team.
Why this matters: Failed attempts from odd places are background noise on any account. A Success from a place you have never been is not — it means someone else got in, and everything else on this list needs checking today.
Note: A company VPN makes your own sign-ins appear in the city where the VPN server sits. If the time and device match what you were doing, an unexpected city is the VPN, not an intruder.
Deep dive: How to Check Your Sign-In Activity in Microsoft 365.
3. Review Your Mailbox Rules and Forwarding (3 minutes)
Rules are where a quiet account takeover hides, so read the whole list rather than skimming it.
In new Outlook for Windows or Outlook on the web:
- Open Outlook and click the gear icon in the top-right corner to open Settings.
- Click Mail in the left column of the Settings pane, then Rules.
- Read every rule in the list. Treat as suspicious any rule that forwards or redirects mail to an address outside your organization, moves incoming mail to Deleted Items or Archive, or marks messages as read automatically.
- Click the trash can icon on a rule you did not create. The rule disappears from the list immediately.
- Click Forwarding in the same Mail list and confirm Enable forwarding is turned off.
In classic Outlook for Windows:
- Click File in the top-left corner, then Manage Rules & Alerts.
- On the Email Rules tab, review every entry in the list.
- Select a rule you did not create and click Delete, then OK. The rule is removed from the list.
Why this matters: A forwarding rule is how a compromise becomes invisible. The classic version forwards anything containing "invoice" or "payment" to an outside address and files the original away, so the conversation continues without you ever seeing it. Rules survive a password change — deleting them is the only fix.
Deep dive: How to Create Email Rules in Outlook, How to Set Up Email Forwarding in Outlook, and How to Check If Your Email Was Compromised.
4. Audit Which Apps Have Access to Your Account (2 minutes)
Every time you clicked "Sign in with Microsoft" on a third-party tool, you granted it standing access. This is where you take it back.
- Go to https://myaccount.microsoft.com and sign in.
- Click Permissions in the left navigation pane. In some organizations this sits under Privacy instead — check there if you do not see it.
- Each entry shows the app name, its publisher, the permissions you granted, and the date you granted them. Read the permissions, not only the name — "Read your mail" and "Send mail on your behalf" deserve more scrutiny than "Read your profile".
- Click any app you no longer use, then click Revoke or Remove permissions and confirm. The app disappears from the list and loses access immediately.
Why this matters: Consent phishing skips your password entirely. Instead of a fake login page, the attacker sends a real Microsoft consent prompt for an app they control — you approve it, and they read your mail without ever knowing your password. MFA does not stop this. Revoking access does.
Deep dive: How to Manage App Permissions and Connected Apps in Microsoft 365.
5. Check Saved Browser Passwords for Reuse and Breaches (2 minutes)
Both Edge and Chrome check your saved passwords against known breach data. Run it once and you get a prioritized list.
In Microsoft Edge:
- Click the three-dot menu in the top-right corner, then Settings > Profiles > Passwords.
- Open Password Monitor. Edge compares your saved passwords against known leaked credentials and lists any matches, with a Change link next to each site.
In Google Chrome:
- Click the three-dot menu in the top-right corner, then Passwords and autofill > Google Password Manager.
- Click Checkup in the left pane, then Check passwords.
- Chrome groups the results into Compromised passwords, Reused passwords, and Weak passwords.
Work down the compromised list first, then the reused list. Change the work-related sites before the personal ones, and never let your work account password appear on any other site.
Why this matters: Attackers rarely guess passwords — they replay ones already leaked from somewhere else. A password reused between a hobby forum and your work account means the forum's breach is now your employer's problem.
Deep dive: How to Manage Saved Passwords in Your Browser and How to Set Up and Use a Password Manager at Work.
6. Confirm Your Recovery Phone and Email (1 minute)
Back to the Security info page from Step 1 — this time reading it for a different purpose.
- Go to https://mysignins.microsoft.com/security-info and find the Phone and Email rows.
- Check the last digits of the phone number and the full address on the email row. Either one is stale if it belongs to a phone you no longer carry, a personal address you abandoned, or a mailbox you cannot open right now.
- Click Change on the row, enter the current number or address, and finish the verification code it sends. The row updates to show the new value.
- If there is no Email row at all, click Add sign-in method, choose Email, and register one. A single recovery route is a single point of failure.
Why this matters: Recovery details are the one setting you discover is wrong at the worst possible moment — locked out, on a deadline, with the reset code going to a phone in a drawer. Sixty seconds now removes a help desk call later.
Deep dive: How to Set Up Self-Service Password Reset (SSPR).
7. Verify Your Device Lock and Encryption (2 minutes)
Close the loop on the physical machine. Leave the browser and open Windows settings.
- Press Windows + I to open Settings.
- Click Accounts in the left sidebar, then Sign-in options. Confirm at least one of Facial recognition (Windows Hello), Fingerprint recognition (Windows Hello), or PIN (Windows Hello) shows as set up.
- Scroll to Additional settings on the same page and set If you've been away, when should Windows require you to sign in again? to Every Time.
- Click Privacy & security in the left sidebar, then Device encryption. Confirm the toggle reads On. On Windows 11 Pro the page is named BitLocker drive encryption instead — open it and confirm your C: drive reads BitLocker on.
- Build the habit that makes all of this work: press Windows + L every time you leave your desk. The lock screen appears instantly.
Why this matters: Encryption covers the one attack no password stops — someone walking off with the laptop and reading the drive directly. Without it, your files are readable by anyone who removes the disk. With it, a stolen laptop is a hardware loss instead of a data breach.
Note: If neither Device encryption nor BitLocker drive encryption appears in Settings, your organization manages it centrally or the hardware does not support it. Send IT a short ticket: "Please confirm whether BitLocker is enabled on my laptop, and turn it on if it is not."
Deep dive: How to Lock Your Computer Quickly on Windows and How to Set Up a Windows Hello PIN.
How Often to Repeat This
Every three months. Put a recurring 15-minute block in your calendar on the first working day of each quarter and run the list top to bottom — it goes faster the second time, because you already know what a clean result looks like.
Run it out of cycle, the same day, after any of these:
- You get a new phone or a new work computer.
- You change roles, teams, or employers.
- You receive an MFA prompt you did not trigger.
- You entered your password on a page you later had doubts about.
- You hear that a service you use has been breached.
Troubleshooting
WARNING
Deleting your last remaining sign-in method locks you out of your own account, and getting back in needs a help desk call and identity verification. Always register the replacement method first, sign out and back in to prove it works, and only then remove the old one.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| The Security info page will not open | Organization uses a different portal | Try https://aka.ms/mysecurityinfo. If that also fails, ask IT which portal your account uses to manage sign-in methods. |
| Delete is greyed out on a sign-in method | It is the only method registered | Click Add sign-in method and register a replacement first, then delete the original (Step 1). |
| Permissions is missing from the left navigation | Consent page hidden in your tenant | Check under Privacy in the same pane. If it is absent there too, ask IT to review the app consents on your account and send you the list. |
| Rules list looks empty but mail still disappears | Rule stored in the other Outlook | Check both versions — classic Outlook keeps some rules on the PC rather than in the mailbox. See How to Fix Outlook Rules Not Working or Running Automatically. |
| Password check reports dozens of exposures | Years of reused passwords | Fix them in priority order: work account, then banking and email, then everything else. A password manager stops the list from regrowing. |
| Device encryption does not appear in Settings | Managed centrally, or unsupported hardware | Send IT a ticket asking them to confirm whether BitLocker is enabled on your laptop and to turn it on if it is not. |
Related Articles
- How to Use the Microsoft Authenticator App
- How to Check Your Sign-In Activity in Microsoft 365
- How to Check If Your Email Was Compromised
- How to Manage App Permissions and Connected Apps in Microsoft 365
- How to Manage Saved Passwords in Your Browser
- How to Set Up and Use a Password Manager at Work
- How to Set Up Self-Service Password Reset (SSPR)
- How to Verify a Suspicious Call or Message from IT
- Understanding Microsoft 365 Account Security — What Protects You and Why