Identify accounts and recovery dependencies
List service names and review status, starting with email, password management and accounts whose loss would block other access. Use your trusted password manager’s own review features when available.
Prioritize important accounts, adopt unique credentials or passkeys, enable supported MFA, and verify service-provided recovery methods.
List service names and review status, starting with email, password management and accounts whose loss would block other access. Use your trusted password manager’s own review features when available.
Choose a password manager that meets your device, recovery and sharing needs, or use an approved existing manager. Replace reused credentials at the actual service and save the new entry securely. Where supported, evaluate a passkey and its recovery path.
Open the service’s security settings and follow its MFA or passkey setup. Prefer phishing-resistant options when supported. Register only devices or authenticators you control and understand how they are backed up.
Use the provider’s actual recovery options, which may include issued backup codes, another authenticator or an account recovery contact. Store them according to your manager or organization’s recovery plan and ensure a lost device will not remove every route.
Use a separate authorized session or device to verify the new sign-in path while retaining a working session until setup is confirmed. Revoke obsolete sessions or methods after reviewing dependencies. Record completion and unresolved recovery issues.
Record non-sensitive account categories, completion status and remaining actions. · Save only the non-sensitive completion register and the next review date.
Inspect an artificial sample to understand the checker’s limited heuristic; never submit a live credential.
Loading your checklist…
CISA recommends strong, unique passwords and a password manager to create and retain them. The manager and its recovery arrangements also need protection.
CISA explains that additional authentication strengthens account protection and recommends phishing-resistant MFA where available. Supported methods and recovery details differ by service.
Verify the real service configuration.
| Check | Evidence to keep |
|---|---|
| Credential | New sign-in succeeds through the intended method |
| Additional factor | Registered authenticator works on the service |
| Recovery | Provider-issued method retained through an independent access path |
| Review notes | Status and follow-up only; no secrets |
Check that recovery still works when the phone or computer normally used to sign in is unavailable.