Google Account Security Checkup from Your Android: A Guided Pass
Your Google account is the load-bearing wall of an Android phone: it holds email, photos, backups, payments and the keys to every service that resets a password by email. Google built a proper audit tool for it, the Security Checkup, and most people have run it never. The full pass takes twenty minutes and the findings are almost always the same three surprises.
Do this on the phone you use daily, signed in as normal. The checkup walks through devices, sign-in methods and third-party access; this guide is the commentary track that tells you what to fix and what to leave alone.

Devices: The List Nobody Reads
The devices section shows everything signed into your account, and it is usually longer than expected. Phones die, tablets get sold, a browser at a borrowed computer stays signed in for years. Anything you do not recognize or no longer own gets signed out from this screen, which takes one tap per device.
Names are imperfect, so judge by the pattern rather than the label: a device type you owned, last active the week you sold it, is the old phone. A device type you never owned, active last night, is the reason this checkup exists. Sign it out, then change the password if anything looks unfamiliar.
Sign-In and Recovery: The Quiet Weak Points
The recovery phone and email are how Google returns the account to you, and how an attacker with your old number returns it to themselves. Verify both are current. Then look at two-step verification: if it is off, turn it on here and now; if it is on, check whether the fallback is SMS and consider upgrading to an authenticator or passkey.
While in this section, glance at recent security activity. Sign-ins from cities you have not visited or devices you do not use deserve the secure-your-account flow, which walks you through password change and sign-outs in one pass.

Third-Party Access: The Permissions Graveyard
Every sign in with Google button you ever tapped created a standing permission, and they accumulate like barnacles. The third-party access section lists each app with what it can see. A workout app from 2022 with access to your contacts, a photo editor that can read your Drive: revoke anything you no longer use, and anything whose access exceeds its job.
The rule of thumb is that access should be current, necessary and revocable without tears. If deleting a permission would break an app you love, the app will simply ask again next time you use it.
Passwords and the Checkup's Sibling Tools
Password Checkup, in the same neighborhood, compares your saved passwords against known breach lists and flags reused ones. Reused passwords on your email and bank are the urgent tier; a reused password on a forum account is a chore for a rainy Sunday. Work the list from the top and let the password manager generate the replacements.
Set a calendar reminder to rerun the whole checkup quarterly. The audit degrades gracefully: devices accumulate, permissions creep, and twenty minutes four times a year keeps the wall load-bearing.
What Twenty Minutes Buys
| Section | Typical finding | Fix time |
|---|---|---|
| Your devices | Old phones still signed in | 3 min |
| Recovery options | Outdated phone number | 2 min |
| Two-step verification | Off, or SMS-only fallback | 5 min |
| Third-party access | Stale app permissions | 8 min |
| Password checkup | Reused or breached passwords | 7 min |
The quarterly routine in five lines:
- Sign out devices you no longer own or recognize.
- Confirm recovery phone and email are current.
- Review two-step verification and prefer passkeys or an app.
- Revoke third-party access you would not grant today.
- Fix flagged passwords starting with email and banking.
Account security is not a product you install but a habit you schedule. The checkup is the habit in its shortest form, and the phone in your pocket is the best place to run it.