Changing a password may sign you out on other devices within seconds, but it does not always sign you out everywhere. Some services immediately invalidate every ordinary web session. Others leave trusted devices, mobile apps, smart TVs, third-party connections, app passwords, passkeys, or access tokens working until you revoke them separately.
That difference matters most when a password was exposed. A successful password change prevents someone from using the old password for a new login, but an attacker who already has a valid session cookie or another authorized sign-in method may not need the password again.
The safest question is therefore not simply, “Did the password change?” It is, “Which forms of access did the service revoke, and which ones are still active?”
Quick Answer
A password change commonly signs ordinary browser and app sessions out within seconds to several minutes, but some services may take up to 24 hours or longer to propagate a separate sign-out-everywhere request. Microsoft, for example, says its account-wide sign-out may take up to 24 hours, while remote sign-out from Microsoft 365 or Office on a specific computer can take up to 72 hours to be detected.
However, a password change alone may never sign out every trusted device or revoke every passkey, OAuth connection, app password, API token, or locally stored file. If the account may be compromised, change the password and then use the service’s device, session, and connected-app controls to revoke access explicitly.
These are planning ranges, not universal guarantees:
| Type of access | Practical planning range after a password change | Can it remain active? |
| Ordinary browser sessions | Seconds to several minutes on services that revoke sessions | Yes, if the service preserves existing sessions |
| Mobile apps | Minutes to 24 hours, often when the app next contacts the server | Yes, if a refresh token or trusted-device exception remains valid |
| Smart TVs and streaming devices | Minutes to 24 hours after explicit device sign-out | Yes, if only the password was changed |
| Microsoft account “Sign out everywhere” | Up to 24 hours | Microsoft publishes this maximum for the separate sign-out action |
| Remote Microsoft 365 or Office sign-out | Up to 72 hours to be detected | Local files and other account sessions may be separate |
| Offline devices | Until they reconnect and the service checks authorization | Yes, while offline; downloaded data may remain afterward |
| OAuth-connected apps | Until access is revoked or the token expires | Yes; a password change may not revoke the app’s authorization |
| App passwords, API tokens, and SSH keys | Until individually revoked, expired, or invalidated by the provider | Frequently |
| Passkeys and security keys | Until removed from the account or device | Frequently |
Why the Old Password and the Current Login Are Different Things
When you type a username and password, the service verifies the credentials. After a successful login, it usually gives the browser or app a temporary digital credential. That credential may be a session cookie, access token, refresh token, or device authorization.
The service uses that credential for later requests so you do not have to re-enter the password for every page, email sync, video, or file upload.
Changing the password changes one authenticator. It does not physically reach into every phone, browser, television, and app to erase what is already stored there. The service must decide whether to invalidate those other credentials on its servers.
A secure service may revoke all sessions immediately. Another may preserve the session used to make the password change so the user is not locked out. A third may keep selected trusted devices active, revoke ordinary sessions but not app passwords, or let existing tokens remain valid until their normal expiration.
NIST’s current digital-identity guidance distinguishes an authentication session from access and refresh tokens. It notes that access tokens and associated refresh tokens can remain valid long after the original authentication session has ended. That is the technical reason “I changed my password” does not always mean “nothing else can get in.”
The Five Access Paths You Need to Check
Most consumer accounts have more than one door. A complete security review considers all five.
1. Password-based login
The new password should stop future logins with the old one once the change reaches the service’s authentication systems. This is usually the fastest part.
2. Existing sessions
A browser or app may already hold a valid session. Whether it is terminated depends on the provider’s rules and whether you selected a sign-out option.
3. Trusted devices and remembered browsers
Some accounts let a device skip repeated verification or use it to approve new sign-ins. The device may remain trusted even after a password change.
4. Alternative authenticators
Passkeys, security keys, authenticator apps, recovery codes, and app-specific passwords are not the same as the main password. Changing one does not necessarily remove the others.
5. Delegated and programmatic access
“Sign in with Google,” “Sign in with Apple,” OAuth connections, personal access tokens, API keys, SSH keys, mail-client authorizations, and smart-home links can give another service or device continuing access without repeatedly presenting the main password.
If the account was merely updated for routine security, reviewing these paths is good housekeeping. If someone else may have accessed the account, checking them is essential.
Password Change, Password Reset, and Sign Out Everywhere Are Not the Same
These actions are often placed near one another in an account’s security settings, but they perform different jobs.
Change password
You normally know the current password, authenticate, and choose a new one. The provider decides which sessions and other credentials are invalidated.
Reset password
You use account recovery because the password is forgotten or the account may be compromised. A well-designed reset flow should give the user a way to invalidate existing sessions or do so automatically. OWASP specifically recommends that password-reset systems either ask whether to invalidate all sessions or invalidate them automatically.
Sign out everywhere
This is an explicit server-side request to revoke sessions across devices. It is generally the right companion action when access by another person is suspected. It may still exclude separate app authorizations, tokens, passkeys, or downloaded data.
Remove a device
This disconnects a selected phone, computer, television, console, or other device. Some services list multiple sessions under one similar device name, so removing every unfamiliar entry is safer than assuming one label represents one session.
Revoke a connected app or credential
This removes a third party’s authorization or disables an app password, passkey, API token, or security key. It is a separate control because the credential may not depend on the current account password.
How Major Services Handle It
Platform behavior changes, so the service’s current security page is always the final authority. These examples show why one universal timeline would be inaccurate.
Google Accounts
They state that changing or resetting a Google Account password signs the user out everywhere except:
- devices used to verify that it is the account owner during sign-in;
- some devices with third-party apps that have account access; and
- helpful home devices that have been given account access.
Google does not publish one guaranteed number of minutes for every session to disappear. If the account may be compromised, do not stop after changing the password.
Go to the Google Account security area, open Your devices, choose Manage all devices, and sign out of unfamiliar devices or sessions. Google warns that several entries with the same device name may represent the same device or multiple devices; sign out of all matching sessions if you cannot confirm them.
Then review:
- linked third-party apps and services;
- app passwords;
- passkeys and security keys;
- recovery phone numbers and email addresses;
- two-step verification methods; and
- recent security activity.
Google’s documentation makes clear that a passkey on a lost or shared device should be removed separately. For automatically created Android passkeys, signing the device out of the Google Account may be part of removing access.
Microsoft Accounts
Microsoft provides a separate Sign out everywhere control in the Advanced security options for a Microsoft account. They say the sign-out process may take up to 24 hours.
That is more dependable than assuming the password change itself closed every session. Review recent activity and registered devices as well, especially when an unknown location or sign-in method appears.
Microsoft 365 and Office licensing sessions have an additional wrinkle. Microsoft says remotely signing a Windows or Mac computer out of Microsoft 365 or Office can take up to 72 hours for the applications to detect. That action affects the Office activation or account session on that device; it should not be treated as a promise that every Microsoft service, Windows login, synchronized file, or locally downloaded document is erased.
Personal Microsoft accounts, work or school accounts, Windows device sign-in, Outlook mail profiles, OneDrive sync, Xbox, and Microsoft 365 app activation can involve overlapping but separate controls. A company-managed account may require an administrator to revoke sessions or disable the user.
Apple Accounts
They explain how to change an Apple Account password, but its current support article does not promise that the password change signs every Apple device out within a fixed period. Apple separately tells users who are securing an account to review the device list and remove devices they do not recognize.
On an iPhone or iPad, the list appears under Settings > [your name]. On the web, it is available through the Apple Account page. Removing an unfamiliar device disconnects it from the account, but you should also review trusted phone numbers, recovery contacts, passkeys or security keys, and unknown sign-in notifications.
Apple’s Personal Safety guidance is especially useful when the concern involves stalking, an abusive relationship, shared access, or a lost device. Safety Check can help review account access and sharing. Take care before making changes if doing so could alert a dangerous person; use a safe device and seek specialized support when personal safety is involved.
Facebook and Instagram
Meta provides controls in Accounts Center under Password and security to review where an account is logged in and select devices to log out. Because Meta’s public help does not give one universal password-change sign-out deadline, the safer approach is to use those session controls directly.
Review Facebook, Instagram, Messenger, Threads, and any linked profiles or connected experiences that share Accounts Center settings. Check contact information and two-factor methods for additions you do not recognize.
Removing saved login information from a phone is different from ending the account’s server session. Likewise, logging out one Facebook device does not necessarily end every other device session.
Netflix and Other Streaming Services
Netflix’s password-change process includes a Sign out all devices option and recommends leaving it selected. Netflix also provides Manage Access & Devices controls for unused or unrecognized devices.
Other streaming services may use device activation codes, household authorization, television apps, consoles, or provider billing. Change the password, select the account-wide sign-out option if available, and inspect the device list. A television that is offline may not display the sign-out until it reconnects.
The same principle applies to shopping, gaming, smart-home, and subscription accounts: use the password change and the explicit session/device control together.
Why Some Devices Stay Signed In
Several technical and practical conditions can delay or prevent an automatic sign-out.
The device is offline
The account provider cannot deliver a live instruction to a disconnected device. When the device reconnects and presents its session or refresh token, the server can reject it. Until then, the app may continue displaying content already stored locally.
The app has a refresh token
Mobile and desktop apps often receive a short-lived access token and a longer-lived refresh token. A password change may invalidate one, both, or neither, depending on the service.
The device is trusted
Providers sometimes preserve trusted devices to prevent accidental lockouts or to maintain a recovery path. Google’s published password-change exceptions are a clear example.
The app uses an app-specific password
Older mail clients, calendars, printers, and devices may use a generated app password instead of the main account password. Revoke app passwords separately if the provider does not invalidate them automatically.
The service uses single sign-on
If you used “Sign in with Google,” Apple, Microsoft, Facebook, or an employer identity provider, the outside website may maintain its own session after the identity-provider password changes. Ending the identity-provider session does not always end the relying website’s local session immediately.
The device uses a passkey or security key
A passkey proves control of a device or credential rather than knowledge of the account password. It can remain a valid sign-in method until removed.
A cookie was stolen
An attacker who steals an authenticated session cookie may bypass the password entirely for the life of that session. OWASP notes that reauthentication and session invalidation are central defenses when session hijacking is possible.
The app has an API token or key
Developer services, automation tools, password managers, command-line clients, and integrations may use personal access tokens, API keys, SSH keys, or deploy keys. GitHub, for example, advises people who suspect compromise to revoke authorizations and review credentials rather than relying only on a password change.
The information is stored locally
Signing out stops future authorized access; it does not retract files, messages, photos, or documents already downloaded to a device. Dropbox explicitly warns that remotely logging a computer out leaves locally synchronized files on that computer unless an eligible remote-wipe option is used.
What to Do If You Think the Account Was Hacked
Use a device you trust. If malware or remote-control software may be present, changing the password on the same compromised device can expose the new password too.
1. Protect the email account first
Email is commonly the recovery route for other services. Secure it before lower-priority accounts if the same person may have access to both.
2. Change the password to a unique one
Do not reuse a password from another account or create a small variation of the old one. A password manager can generate and store a unique password.
3. Choose “sign out everywhere”
Use the provider’s explicit session-revocation option. If it is unavailable, remove unfamiliar devices and sessions one by one.
4. Remove unknown devices
Check phones, computers, browsers, TVs, consoles, smart-home devices, and repeated sessions with similar names. Save screenshots first if you may need evidence of unauthorized access.
5. Revoke alternative access
Review and remove anything unfamiliar:
- OAuth-connected apps;
- app passwords;
- passkeys and security keys;
- personal access tokens and API keys;
- SSH or deploy keys;
- delegated mailbox access;
- forwarding rules;
- recovery codes; and
- remembered browsers.
6. Verify recovery information
Remove unknown email addresses, phone numbers, recovery contacts, authenticator methods, and account aliases. An attacker who added a recovery path may be able to return after the password changes.
7. Turn on multifactor authentication
CISA recommends multifactor authentication because a stolen password alone is then insufficient for access. Prefer phishing-resistant methods such as passkeys or security keys when the service and your circumstances support them.
8. Review recent activity and account changes
Look for sent messages, forwarding rules, purchases, security-setting changes, new applications, deleted files, altered contact details, and logins from unknown locations.
9. Secure other accounts that reused the password
Change every reused password. Credential-stuffing attacks try a known username and password on unrelated services.
10. Check the device itself
Update the operating system and security software, remove unknown browser extensions or apps, and scan for malware. If a lost or stolen device contained sensitive local data, use the manufacturer’s lost-device or remote-erase options when available.
How to Confirm That Other Sessions Are Gone
Do not test only on the device where the password was changed. That session may be intentionally preserved.
Review the provider’s device or session page
Check the last activity time, approximate location, browser, device type, and sign-in method. Remember that locations can be imprecise because of mobile networks, VPNs, and internet-provider routing.
Test a second device you control
Open the service on a phone, computer, or television that was previously signed in. Refresh the app and attempt a server action, such as loading new mail or account settings. Seeing an old inbox or downloaded video does not prove the session is still authorized.
Wait for the provider’s published maximum
If Microsoft says its account-wide action may take up to 24 hours, do not declare failure after ten minutes. If the service gives no timeline, recheck after several minutes and again after the device reconnects.
Check recent activity again
New unauthorized activity after the password change can indicate a surviving session, recovery method, connected app, compromised device, or a second account-access path.
Confirm that security alerts reached you
Most major providers send notices after password, recovery, or device changes. If an expected message never arrives, verify that the notification and recovery addresses were not altered.
Does Clearing Cookies Sign You Out Everywhere?
No. Clearing cookies signs that browser out of many websites by deleting its local session cookies. It does not revoke sessions stored on other browsers or devices.
It also does not normally revoke mobile-app tokens, passkeys, API keys, or connected applications. For security, server-side sign out everywhere is much stronger than clearing one browser.
Conversely, a server-side sign-out can invalidate the session even while the old cookie remains stored locally. The cookie simply stops being accepted when the browser tries to use it.
Does Changing a Saved Password in the Browser Sign Devices Out?
No. Editing a password in Chrome, Edge, Firefox, Safari, or a standalone password manager updates the credential stored for future logins. It does not notify the website that its account password changed and does not invalidate current sessions.
Change the password through the account’s official website or app first. Then update the saved entry after the change succeeds.
If the password manager itself may be compromised, change its master password, review signed-in devices and emergency-access settings, rotate exposed account passwords, and revoke sessions according to that provider’s guidance.
What About Email Apps, Printers, and Smart-Home Devices?
These devices often expose the exceptions people notice days later.
Email applications
Modern mail apps may use OAuth tokens. Older clients may use app passwords. A main password change can interrupt mail immediately, at the next sync, or not until the separate authorization is revoked.
Also inspect forwarding rules, filters, delegates, and connected mailbox apps. Signing an attacker out does not undo a forwarding rule they created.
Printers and scanners
A multifunction printer may store an app password or OAuth authorization for scan-to-email or cloud storage. Revoke the credential and configure a new one if needed.
Smart speakers and home devices
Google specifically lists some helpful home devices among its password-change exceptions. Apple, Amazon, and other ecosystems may have their own device and household-sharing controls. Review the home membership and linked-service lists, not only the main device list.
Televisions and consoles
Streaming sessions can remain active until the service revokes the device authorization or the app reconnects. Use Manage Devices or Sign Out All Devices.
Cars and rental devices
Vehicles can retain streaming, navigation, contact, garage-door, and account connections. Hotel televisions, rental cars, borrowed tablets, and public computers should be removed from the relevant account history after use.
Work, School, and Shared Accounts
An employee changing a password may not control every session issued by the organization’s identity provider, virtual private network, email platform, cloud apps, or single-sign-on system.
An administrator may need to:
- revoke active sessions;
- reset multifactor methods;
- disable app passwords;
- revoke OAuth grants and refresh tokens;
- remove registered devices;
- invalidate certificates or security keys;
- rotate API and service-account credentials;
- review mailbox forwarding and delegation; and
- disable the account entirely.
Shared household or business passwords create another problem: someone may still be authorized even though the password changed. Remove former users, household members, profiles, delegates, and shared vault access through the service’s permission controls.
Do not use one person’s password as a substitute for proper user accounts and permissions. Individual accounts make it possible to remove one person’s access without disrupting everyone else.
Why Your Own Device May Stay Signed In
Remaining signed in on the device used to change the password is not proof that the change failed. The provider may preserve the current verified session so you can finish the security review.
Other reasonable explanations include:
- the screen displays cached data while the device is offline;
- the app has not tried to refresh its access token;
- the device is a trusted verification device;
- biometric unlock opens locally stored app data;
- the app uses a passkey or separate token; or
- the service applies revocation in stages.
To test correctly, refresh from the server, open a protected security setting, or use the provider’s session list. Do not assume that seeing an old message or photo means the account can still retrieve new information.
Can You Force an Immediate Sign-Out?
You can request immediate revocation, but the provider controls implementation. The best available sequence is:
- Change or reset the password.
- Select Sign out everywhere or log out all sessions.
- Remove unrecognized devices.
- Revoke connected apps, app passwords, passkeys, tokens, and keys.
- Disable or lock the account temporarily if the provider offers that option and risk remains high.
An offline device may not show the result until it reconnects. Local copies cannot be pulled back by session revocation alone. If the provider publishes a maximum processing time, use that specific figure; otherwise, no one outside the provider can truthfully guarantee an exact cutoff.
Common Mistakes After Changing a Password
Assuming the old password is the only threat
Attackers can preserve access with cookies, forwarding rules, OAuth apps, recovery methods, or tokens.
Reusing the new password
If another breached service exposes the same password, the account is vulnerable again.
Approving an unexpected verification prompt
An attacker may try to sign in after the change and trigger a push request. Deny prompts you did not initiate.
Forgetting the recovery email
Securing a shopping or social account while leaving its email recovery account exposed solves only half the problem.
Removing a device without revoking its other credentials
A laptop can have a browser session, email token, passkey, and downloaded files. One device-list action may not address all four.
Confusing a Wi-Fi password with an account password
Changing the home Wi-Fi password disconnects devices from that wireless network. It does not sign them out of Google, Facebook, Microsoft, banking, shopping, or streaming accounts once they connect through another network.
Changing passwords repeatedly without investigating
If a compromised device, malicious forwarding rule, unknown recovery method, or stolen session remains, repeated password changes may not solve the underlying problem.
Related Articles
If you are working on related projects or researching similar topics, these guides may also help:
- How Long Does It Take to Remove Personal Information From the Internet?
- How Long Does It Take for a Device to Stop Sharing Your Location?
- How Long Does It Take to Factory Reset a Phone?
- How Long Does It Take for a Deleted File to Be Permanently Erased?
- How Long Does It Take to Clear Cache on a Device?
Frequently Asked Questions
Does changing a password log you out of every device?
Not always. It depends on whether the provider revokes current sessions and alternative credentials. Use the service’s sign-out-everywhere and device-management controls when complete logout matters.
How quickly should other devices be signed out?
Many ordinary sessions are invalidated within seconds or minutes, but some services take longer. Microsoft says its separate account-wide sign-out can take up to 24 hours. Offline devices may not show the change until they reconnect.
Why am I still signed in after changing my password?
The service may preserve the current trusted session, the app may be offline, cached content may still be visible, or the app may use a refresh token, passkey, or other credential that was not revoked.
Can someone still access my account with the old password?
They should not be able to start a normal new login after the password change is active. However, an existing session or separate authorized credential can sometimes continue working without the old password.
Does “sign out everywhere” work immediately?
It is usually the strongest session-revocation option, but not every provider promises immediate completion. Follow its published processing time and remember that offline content and separate credentials may remain.
Will changing my Google password sign out every device?
Google says it signs the account out everywhere except certain verification devices, some third-party app devices, and helpful home devices. Review the Google device list and connected apps separately.
How long does Microsoft take to sign out everywhere?
Microsoft says its account-wide Sign out everywhere action may take up to 24 hours. Remote Microsoft 365 or Office sign-out on a computer may take up to 72 hours for the apps to detect.
Does changing my Apple Account password remove unknown devices?
Apple does not publish one blanket promise that a password change removes every device. Its security guidance tells users to inspect the Apple Account device list and remove devices they do not recognize.
Does changing a password revoke a passkey?
Not necessarily. Passkeys are separate authenticators. Review the account’s passkey list and remove any associated with a lost, shared, or unfamiliar device.
Does changing a password revoke third-party apps?
Not always. An OAuth-connected app can hold authorization that does not depend on repeatedly submitting the main password. Revoke suspicious or unnecessary apps from the account’s connected-app settings.
Will signing out remotely delete files from another device?
Usually not. It blocks future authorized access but does not automatically retract downloaded files. Dropbox, for example, says synced local files remain after ordinary remote logout unless an eligible remote-wipe feature is used.
Does clearing browser cookies sign out all my devices?
No. It affects that browser’s local sessions. Other browsers, phones, apps, televisions, and tokens remain separate.
Should I change every password if one account was hacked?
Change the password on every account that reused the compromised password. Unique passwords prevent one breach from becoming access to multiple unrelated services.
Is changing the password enough after an account takeover?
No. Also revoke sessions, remove unknown devices and recovery methods, review connected apps and tokens, enable multifactor authentication, inspect recent activity, and check the device used to make the change.
Quick Summary
A password change may sign ordinary sessions out within seconds or minutes, but it does not guarantee that every device and access method is disconnected. Microsoft says its separate account-wide sign-out can take up to 24 hours, while remote Microsoft 365 or Office sign-out can take up to 72 hours. Other providers do not publish one universal deadline.
Existing session cookies, trusted devices, OAuth refresh tokens, app passwords, passkeys, security keys, API tokens, smart-home authorizations, and offline data may survive the password change. Google explicitly documents several password-change exceptions, while Apple and Meta provide separate device-removal or session controls.
When compromise is possible, use a trusted device, secure the recovery email, create a unique password, select sign out everywhere, remove unknown devices, revoke alternative credentials, verify recovery information, enable multifactor authentication, and review recent activity. A successful password change closes the old-password door; a complete account-security review checks every other door too.
Sources & References
- Google Account Help: Change or Reset Your Password
- Google Account Help: See Devices With Account Access
- Google Account Help: Manage Links Between Your Google Account and Apps
- Google Account Help: Manage and Remove Passkeys
- Google Account Help: Sign In With App Passwords
- Microsoft Support: Sign Out of Your Microsoft Account Everywhere
- Microsoft Support: Sign Out of Microsoft 365 or Office
- Microsoft Support: Review Recent Microsoft Account Activity
- Apple Support: Change Your Apple Account Password
- Apple Support: Check Your Apple Account Device List
- Apple Personal Safety User Guide: Keep Your Apple Account Secure
- Meta Help Center: Log Out of Facebook on Another Device
- Netflix Help Center: Change or Reset Your Password
- NIST SP 800-63B: Session Management
- OWASP: Forgot Password Cheat Sheet
- OWASP: Session Management Cheat Sheet
- CISA: Multifactor Authentication
- GitHub Docs: Preventing Unauthorized Access
- Dropbox Help: View Devices and Log Out Remotely
Editorial Review
Reviewed by Claire Bennett, Managing Editor
Last reviewed: August 2026
Quick Answer Guide publishes practical, research-based answers to common questions about money, technology, health, travel, home improvement, and everyday life. Content is reviewed using official government resources, educational institutions, industry publications, and other authoritative sources when appropriate. Articles are updated periodically to improve accuracy and usefulness.
