Understand the separate credential
An app password is a provider-generated credential intended for a particular application or older sign-in workflow. It is separate from your normal account password and may let a client connect without the interactive prompt you expect during a browser sign-in. Support and eligibility vary between providers and account types.
Do not create app passwords to bypass your organisation's security policy. This exercise reviews existing credentials and removes those that no longer serve an approved purpose.
Trace each credential to a client
- Open the provider's security settings from a genuine bookmark. Locate the app-password section if your account supports it. Its absence is not a reason to weaken the account's security options.
- List the entries and labels that are actually displayed. Compare them with active mail applications, scanners and other integrations. A label such as laptop may be too vague to establish an owner.
- For an uncertain entry, ask the responsible user or administrator which device uses it. Choose a maintenance window if revocation might interrupt a required process.
- Revoke one retired credential through the provider's supported control. Where a current client supports modern interactive authentication, migrate it using the vendor's normal setup rather than distributing a shared replacement secret.
Verify the affected client
An owned test client using the revoked credential should fail its next authenticated connection. Previously downloaded mail may remain visible, so opening the inbox is not a useful test by itself. Try a normal synchronisation and inspect the resulting authentication status without exposing the credential in logs or screenshots.
Protect the remaining entries
Use one clearly labelled credential for each approved purpose when the provider supports that pattern. Store credentials in a protected vault, not an unencrypted note beside the device. Avoid embedding them in a publicly accessible script or exporting full application configuration for troubleshooting.
Retire the exception when possible
Legacy access can outlive the equipment that needed it. Review app passwords when replacing a computer, removing a scanner or investigating unusual mailbox activity. Changing the main password may affect app passwords differently between services, so use the provider's explicit revocation controls rather than assuming one action covers every credential.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.