Checking devices and applications that accessed your account

Plan requirement

Subscription Any plan
Access Admin

What has been signing in to your account, and what to do when something on the list is unfamiliar.

Check it

  1. Open the security settings in Admin Center.
  2. Review the devices and applications with access.
  3. Look at when each was last active.
  4. Revoke anything nobody recognises.

What you are looking for

  • Applications nobody remembers connecting. Often a trial from two years ago.
  • Devices belonging to people who left.
  • Access from places your team does not work.
  • Anything that has not been used in months and still holds access.

Unused access is the risk

An integration nobody uses still has a key and still has whatever permissions it was given. Nobody is watching it, and nobody would notice if it started behaving differently.

Revoke and see what breaks

For anything genuinely unrecognised, revoke it and wait. If something stops working, you now know what it was and can reconnect it deliberately.

Leaving it because nobody is sure is how these lists grow.

Tell people first

Revoking a device signs somebody out. Doing that to a colleague mid-shift without warning is avoidable.

Make it quarterly

Alongside your access review. This list only grows on its own, and reviewing it is one of the few security tasks that regularly finds something.

If something looks genuinely wrong

Access from an unexpected country, or an application nobody can account for: revoke it, change the credentials involved, and contact pluscloud support the same day.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.