What to Do If Someone Has Accessed Your Windows Account Without Permission

How to check depending on whether it's physical or remote access, and the steps to protect yourself immediately.

Intermediate 2 min read Published on 2026 By Equipo SolucionaPC

You suspect someone has used your account without your permission. First, let's tell apart two very different situations, because each one is checked and fixed differently.

Physical access to your PC (someone in your home, your office) or remote access to your Microsoft account (from somewhere else, over the internet)? These are different threats — follow the section that matches your case.

If you suspect physical access (someone used your PC)

  1. Press Windows + R → type eventvwr.msc → Enter.
  2. Windows Logs → Security.
  3. "Filter Current Log" → type 4624,4625 (successful and failed sign-ins).
  4. Check the dates and times — if there's activity at moments you know you weren't using the machine, that's your answer.

Tip: you can also check powercfg /lastwake from the command prompt, which tells you what caused the machine's last wake-up — useful if you suspect someone used it while it was asleep.

If you suspect remote access (to your Microsoft account)

  1. Go to account.microsoft.com with your account → "Recent activity".
  2. Check the list of sign-ins — Microsoft shows the approximate location and device for each one.
  3. If you see anything you don't recognise, mark "This wasn't me" next to that sign-in.

What to do immediately in both cases

  • Change your password — do it from another device if you suspect the computer in question may still be compromised.
  • Turn on two-step verification if you don't have it yet, in your Microsoft account's security settings.
  • Check your email forwarding rules — some attacks set up hidden automatic forwarding to keep seeing your messages even after you change the password.

Warning: if you suspect an active intrusion is happening right now (not something in the past), don't shut the machine down abruptly — disconnect it from the internet (Wi-Fi or cable) instead. Shutting it down erases information in RAM that could help you understand what happened; disconnecting it from the network cuts off access just the same without losing that information.

Preventing it from happening again

If the access was physical (someone in your home), password protect your account if you didn't already, and consider creating separate accounts for each person who uses the machine instead of sharing a single one. If it was remote, two-step verification is the most effective protection — even with your password, they couldn't get in without the second step.

Frequently asked questions

How do I tell whether the access was physical or remote?

Windows Event Viewer (Windows Logs > Security) reflects physical sign-ins on the machine. The 'Recent activity' page on account.microsoft.com reflects access to your Microsoft account, including remote ones, with approximate location.

Should I shut down the computer if I think someone is accessing it right now?

It's better to disconnect it from the internet (Wi-Fi or cable) instead of shutting it down. Shutting it down erases information in RAM that could be useful for understanding what happened; disconnecting it from the network cuts off access just as effectively.

Does two-step verification prevent this in the future?

Yes, it's the most effective protection against unauthorised remote access — even if someone gets your password, they wouldn't be able to complete the sign-in without the second verification step.

Share: