Przejdź do zawartości

6. Checking Your Own Sign-in Activity

LESSON 6 OF 6 · 7 MIN

Checking Your Own Sign-in Activity

You do not need to be technical to spot a break-in. Both Microsoft and Google let you see, in plain language, where your account has been used.

Where to look

Microsoft 365: your account page, section Sign-in activity or Recent activity.
Google: your Google Account, section Security, then Recent security activity and Your devices.

You will see a list of sign-ins with a time, a rough location, and a device or browser.

How to read it — this part matters

The instinct is to look at the country and panic at anything foreign. That is misleading. In the case from Lesson 1, the employee genuinely was abroad, and those foreign sign-ins were perfectly legitimate. The attacker's sessions looked less alarming at first glance.

The reliable signal is what kind of connection it came from. Your own sign-ins come from home internet providers or mobile networks. Attackers usually appear from hosting providers and data centres — commercial server networks that no ordinary employee uses to read email.

What to report
  • A sign-in at a time you were definitely asleep or offline
  • A device or browser you have never used
  • Several sign-ins from places far apart within a short period
  • Anything at all that simply feels wrong

Send us a screenshot. We can tell within minutes whether it was you on a hotel network or somebody else on a rented server.

Make it a habit

Once a month is enough. It takes two minutes, and it is the single easiest way to catch a compromise that slipped past everything else.

You have finished the course. If you only remember one thing, make it this: a code you did not ask for means somebody already has your password — deny it, change it, and tell us.

Komentowanie nie jest włączone w tym kursie.