Your sign-in methods, active sessions, and recent account activity in one place
The single place to control who can sign in to your account and on which devices.
The Security page at Settings > Securityis your personal command center for account safety. It shows every way your account can be signed into, every device currently signed in, and everything that has happened to your account recently. Every user has this page — no admin role is required to manage your own security.
The page is organized top-to-bottom around increasing scope.
How you prove it's you. Four cards:
A list of every device and browser currently signed in to your account, with device type, IP address, city and country, and last-active time. Your current device is marked This device. You can revoke any other session individually, or sign out every other session at once.
Link or unlink external identity providers (Google, Microsoft). Shows whether a password is set and which provider accounts are connected. The page blocks you from removing your only sign-in method so you never get locked out.
Sign-ins and security events from the last 30 days — successful logins, failed attempts, MFA events, password changes, session revokes, provider links, and any events the system flagged as unusual. A This wasn't me button lets you report a suspicious sign-in. You can export the activity log as CSV.
Two links at the bottom — Export my data and Delete account— both hand off to the data controls page on your profile.
Step-up reauth protects the actions that matter.
When you remove an MFA method, unlink a sign-in provider, set your first password, or sign out every other device, the app asks you to re-verify your identity first. This is step-up reauth: proving it really is you before the app lets you weaken or change how you sign in. The dialog uses whatever methods you already have — password, authenticator, or passkey. Verification lasts a few minutes, so you only re-verify once per burst of changes.
Who sees this page and what they see there.