How to lock down your Google account
I run a handful of Google accounts across different projects, a personal Gmail I’ve had since university, a couple of Workspace accounts tied to client sites, and a YouTube-linked account for a channel. Every one of them is a single point of failure. If someone gets into the Gmail, they get password resets for half the other services tied to it, plus Drive, Photos, Calendar, and whatever OAuth apps I forgot I’d connected three years ago.
This is for anyone who has never actually walked through Google’s own security settings end to end, individuals, freelancers, and small operators managing more than one account. It’s not about paranoia, it’s about closing the doors account takeovers actually walk through: SMS-only 2FA, stale OAuth grants, forwarding rules an attacker plants after a phish, and recovery info that points nowhere useful.
By the end you’ll have 2-step verification running on a phishing-resistant method, a clean list of connected apps, verified sessions, and, if the account is worth it, enrollment in Google’s Advanced Protection Program. Budget 20-30 minutes per account.
what you need
- A Google account you can currently log into (if you’re already locked out, that’s a recovery flow, not this guide)
- A phone you control, for the initial 2SV setup
- Optional but recommended: a hardware security key. I use a YubiKey 5 NFC (~US$50) and keep a Google Titan Security Key (~US$30) as backup
- A password manager, 1Password or Bitwarden, if you don’t already have one
- Access to whatever recovery email you set years ago, dig it up now if you’re not sure it’s current
- 20-30 minutes per account, uninterrupted
- If you manage a Google Workspace domain: admin console access, this changes step 7 later on
step by step
1. run the Google Security Checkup
Go to Google’s Security Checkup while logged into the account. It walks through recent security activity, signed-in devices, third-party access, and recovery info in one pass.
Expected output: a scored list, usually flagging at least one stale device or an app you don’t recognize.
If it breaks: if the checkup won’t load or hangs on “checking,” it’s almost always a browser extension interfering, ad blockers doing aggressive script blocking are the usual culprit. Try it in an incognito window before assuming the account itself is compromised.
2. turn on 2-step verification
If 2SV isn’t already on, go to the 2-Step Verification settings and enable it. Start with your phone number as the first factor, you’ll upgrade this in step 3.
Expected output: the account now prompts for a second factor on new device sign-ins.
If it breaks: if you don’t receive the SMS code, check the number has the correct country code, Google defaults to whatever region it thinks you’re in, which is wrong more often than you’d expect for accounts set up while traveling. Use “call me instead” as a fallback.
3. switch to a passkey or security key as your primary method
SMS is the weakest 2FA method because it’s vulnerable to SIM swapping. NIST’s digital identity guidelines deprecated SMS as an authenticator for exactly this reason. In your Google Account, go to Security > Passkeys and security keys, add a passkey (stored via your device’s built-in authenticator, Face ID, Windows Hello, or a hardware key like a YubiKey), and set it as your default sign-in method.
Expected output: signing in on a new device now prompts for the passkey or key touch instead of a text code.
If it breaks: if the browser doesn’t detect your security key, check it’s plugged into a port that supports it, some USB-C hubs strip the necessary protocol, or that Bluetooth is on if you’re using a BLE key like the Titan.
4. review and revoke third-party app access
Under Security > Third-party apps with account access, go through every entry. Anything you don’t recognize, haven’t used in over a year, or granted broad Gmail/Drive scopes to for a one-off task, revoke it.
Expected output: a shorter list, ideally under 10 entries, all recently used and all with scopes you can justify.
If it breaks: revoking access sometimes breaks an integration you forgot you rely on, a calendar sync tool for example. If something stops working within a day of doing this step, that’s your answer, reconnect it deliberately with minimum scopes.
5. check active sessions and connected devices
Security > Your devices lists everything currently signed in. Sign out of anything you don’t recognize or haven’t used recently, an old laptop, a friend’s browser you logged into once, a phone you sold.
Expected output: the device list matches only hardware you currently own and use.
If it breaks: if a device you don’t recognize keeps reappearing after you sign it out, that’s a sign the password itself may be compromised. Change it immediately and re-run the checkup from step 1.
6. update recovery phone, recovery email, and generate backup codes
Under Security > Ways to verify it’s you, confirm both the recovery phone and recovery email are current and under your control, not an old number or an email account that also needs securing separately. Then generate backup codes and store them in your password manager, not a screenshot on the same phone.
Expected output: recovery info current, 10 backup codes saved somewhere other than your primary device.
If it breaks: if you can’t access the current recovery email at all, update it now while you’re still logged in. This is the step people skip and regret during an actual lockout.
7. enroll in Advanced Protection Program for high-value accounts
If this account touches money, client access, or anything you genuinely cannot afford to lose, enroll in Google’s Advanced Protection Program. It requires two physical security keys, blocks non-Google apps from accessing Gmail and Drive data by default, and adds extra scrutiny to account recovery requests.
Expected output: the account now requires a physical key for every new sign-in, and third-party app access is restricted.
If it breaks: Advanced Protection can lock you out hard if you lose both keys. Register a second key as backup before enrolling, and store it somewhere physically separate from your primary device, I keep mine in a drawer at a different location, not next to my laptop bag.
8. audit Gmail forwarding rules and filters
Go to Gmail Settings > Forwarding and POP/IMAP, and separately Settings > Filters and Blocked Addresses. Attackers who get temporary access often plant a silent forwarding rule so they keep reading mail even after you change the password. Delete anything you didn’t set up yourself.
Expected output: no unrecognized forwarding addresses, no filters silently archiving or forwarding password-reset emails.
If it breaks: if you find a forwarding rule you don’t recognize, treat it as a confirmed compromise, not a maybe. Change the password, revoke all sessions, and go back through steps 2-6 from scratch.
9. lock down Chrome sync and saved passwords
If you use Chrome signed into this account, check Settings > Autofill and passwords, and Settings > Sync. Anyone with the browser unlocked can pull every saved password in plaintext through Chrome’s own password manager UI. Set a device screen lock if you haven’t, and consider migrating saved passwords into 1Password or Bitwarden instead of relying on Chrome as the vault.
Expected output: credentials live in a dedicated password manager, Chrome sync scoped to only what you need synced.
If it breaks: migrating out of Chrome’s password manager can miss entries tied to old, deleted sites. Export the CSV first (Settings > Passwords > ⋮ > Export) before turning sync off, so you’re not hunting for a login later.
common pitfalls
- Staying on SMS-only 2FA. It’s better than nothing, but SIM swap attacks are well documented enough that NIST and most major platforms treat SMS as a fallback, not a primary factor. Move to a passkey.
- Recovery email points to another compromised account. I’ve seen this loop where the recovery email is an old Yahoo or Hotmail account nobody has secured in a decade. Your recovery chain is only as strong as its weakest link.
- Leaving old OAuth grants alive. A browser extension or a game you tried once in 2023 still has standing access to your Drive files unless you revoke it. Check step 4 quarterly, not once.
- Screenshotting backup codes to the same phone that’s also your 2FA device. If the phone is lost or compromised, both factors go with it. Put them in a password manager or print them.
- Operators reusing one recovery phone number across many managed accounts. If you run multiple Workspace or client accounts, a single recovery number becomes a single point of failure across all of them. I learned this one the hard way after a number port took longer than expected and locked me out of three accounts for a weekend.
scaling this
At 10x, a handful of personal or side-project accounts, do this manually, account by account, and track what you did in a shared password manager vault so you’re not repeating the checkup from memory. Twenty to thirty minutes each, budget half a day total.
At 100x, a small team or agency managing client Google accounts, this stops being a personal checklist and becomes a Workspace admin policy. If you’re on Google Workspace, the admin console lets you enforce 2SV org-wide, set context-aware access rules, and see a security dashboard across every user instead of auditing accounts one by one.
At 1000x, managing accounts at real scale, manual auditing doesn’t hold up. This is where a tool like GAM, an open-source command-line tool for Google Workspace admins, earns its keep. You script bulk audits and enforcement instead of clicking through the admin console user by user:
# enforce 2-step verification for every user in an org unit
gam update org "Sales" 2sv_enforcement on
# list every third-party app with access, across the whole domain
gam all users print apptokens
Pair that with a quarterly access review pulled via the Admin SDK API rather than trusting anyone to remember to check manually. If you’re also managing separate browser profiles per client account to avoid cross-contamination between sessions, that’s a related but different problem, antidetectreview.org covers the browser isolation tooling for that specific use case.
where to go next
Once your Google account itself is locked down, the next question is whether any of your other accounts have already been exposed somewhere else. Start with how to check if your accounts were in a breach, then work through how to browse without being fingerprinted, since session and device fingerprinting is a separate attack surface from account credentials. For the broader picture, how to actually stay private online in 2026 ties all of this into one setup. More guides like this live on the blog.
Written by Xavier Fok
disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-07-19.