6. Checking Your Own Sign-in Activity
Checking Your Own Sign-in Activity
You do not need to be technical to spot a break-in. Both Microsoft and Google let you see, in plain language, where your account has been used.
Where to look
Microsoft 365: your account page, section Sign-in activity or
Recent activity.
Google: your Google Account, section Security, then
Recent security activity and Your devices.
You will see a list of sign-ins with a time, a rough location, and a device or browser.
How to read it — this part matters
The instinct is to look at the country and panic at anything foreign. That is misleading. In the case from Lesson 1, the employee genuinely was abroad, and those foreign sign-ins were perfectly legitimate. The attacker's sessions looked less alarming at first glance.
The reliable signal is what kind of connection it came from. Your own sign-ins come from home internet providers or mobile networks. Attackers usually appear from hosting providers and data centres — commercial server networks that no ordinary employee uses to read email.
- A sign-in at a time you were definitely asleep or offline
- A device or browser you have never used
- Several sign-ins from places far apart within a short period
- Anything at all that simply feels wrong
Send us a screenshot. We can tell within minutes whether it was you on a hotel network or somebody else on a rented server.
Make it a habit
Once a month is enough. It takes two minutes, and it is the single easiest way to catch a compromise that slipped past everything else.
You have finished the course. If you only remember one thing, make it this: a code you did not ask for means somebody already has your password — deny it, change it, and tell us.