LEARNING TOPIC
Account security
Passkeys, access reviews and recovery routes.
Create a passkey and test your recovery route
Practise a phishing-resistant sign-in without losing your existing account recovery options.
Review apps connected to your Google account
Distinguish signing in with Google from giving an app access to account data.
Review account sessions and sign out old devices
Identify stale sessions without treating every unfamiliar device label as an attacker.
Separate administrator access from everyday work
Reduce the tasks that run with elevated privileges while retaining a tested administration route.
Make an account recovery map without exposing secrets
Find circular dependencies before a lost phone prevents access to every important account.
Respond to an MFA prompt you did not initiate
Handle repeated approval requests without accidentally authorising an attacker.
Find and retire old app passwords
Reduce long-lived credentials left behind by mail clients and retired integrations.
Offboard a user with an access inventory
Remove access systematically while preserving required business records.
Store recovery codes for a lost-device scenario
Keep emergency sign-in material available without leaving it beside an exposed password.
Verify a support caller before granting remote access
Create a callback process that prevents a convincing voice from becoming administrator access.