Start here if you’re in a hurry
If you think someone is monitoring your phone right now, Locking down your Android is the fast walkthrough — Play Protect, permission checks, accessibility and device-admin audits, in the order that matters most urgently. Read Safety first: before you remove anything before you change anything, since some monitoring apps notify the person controlling them when settings change, and removing something can destroy evidence you need later.
This guide is the fuller picture: every layer of Android security, in order, for when you have time to do it properly. It assumes close-to-stock Android (Pixel-style) unless noted — other manufacturers rename and relocate some screens, flagged as they come up.
Layer 1: the baseline
Screen lock quality
Everything else in this guide sits on top of your screen lock. Android supports five options: None, Swipe, Pattern, PIN, and Password, and Google’s own guidance recommends a 6-digit PIN over a shorter one, noting that “a strong password is the most secure screen lock option” (Google Android Help). Set or check yours at Settings → Security (path and label vary by manufacturer — search Settings for “Screen lock” if you can’t find it).
Two related settings worth checking in the same menu:
- Auto-confirm unlock. If you use a PIN longer than 6 digits, Android can skip the extra tap to submit it — convenient, but our own take is that skipping the confirmation tap makes a longer PIN easier to shoulder-surf, and Google itself is direct about the trade-off: it “may decrease the security of your device” (Google Android Help).
- Extend Unlock (formerly Smart Lock). This keeps your phone unlocked in certain conditions — on your body, at a trusted place, near a trusted Bluetooth device — for up to 4 hours at a time (Google Android Help). Google flags real risks here: a trusted location “is an estimate” that “can go out beyond the walls of your home,” and location or Bluetooth signals “can be copied or manipulated” by someone with the right equipment (Google Android Help). If you share a home with someone you don’t fully trust, turn it off entirely at Settings → Security & privacy → More security & privacy → Extend Unlock.
Updates
Android updates arrive in two channels: full Android version updates, and the more frequent Google Play system updates that patch security issues without a full OS upgrade (Google Android Help). Check both at Settings → About phone → Android version, which shows your Android version, security patch level, and Play system update date. Google notes that “update schedules vary by device, manufacturer, and mobile carrier” — how long a given phone keeps getting patches depends entirely on who made it (Google Android Help). If your phone hasn’t taken a security update in several months, check your manufacturer’s support site for that model’s update policy.
Back up before you change anything else
The steps below sometimes involve wiping or resetting things, so set a PIN, pattern, or password (not swipe) now, which ensures your automatic and manual backups are encrypted (Google Android Help).
Layer 2: your Google account
Your Google account, not just the phone in your hand, is usually the bigger target — whoever controls it can reach Gmail, Photos, Drive, and location history from any device.
Run a Security Checkup
Google’s Security Checkup is a guided pass through your account’s security settings, with personalized recommendations to strengthen it (Google Account Help). Run it from Settings → Google → Manage your Google Account → Security.
While you’re there, review Your devices at google.com/devices, which lists every device currently or recently signed in to your account. Sessions you don’t recognize can be signed out individually, and Google notes that “if multiple sessions appear for the same device type, they might all be on one device or multiple devices” — when in doubt, sign out of all sessions under an unfamiliar device name (Google Account Help). If a new device signs in, Google sends a “Did you just sign in?” notification to your already-signed-in Android devices; reviewing it, then changing your password if it wasn’t you, is the fastest way to shut down unauthorized access (Google Account Help).
2-Step Verification
2-Step Verification adds a second check beyond your password — a prompt to your phone, a text code, or a passkey — so that “even if someone gets your password online, they won’t also have your phone” (Google Account Help). Google’s framing is direct: “password theft is the most common way accounts are compromised,” largely through phishing messages and lookalike sites (Google Account Help).
Passkeys are Google’s recommended alternative to passwords entirely: you sign in with your fingerprint, face, or screen lock, and because a passkey “can only exist on your devices,” it can’t be phished or handed over by mistake the way a password can (Google Account Help). If you lose your phone, backup codes and a recovery email keep you from being locked out — set these up before you need them.
Advanced Protection Program (account-level)
The Advanced Protection Program is Google’s strongest account security tier, designed to “safeguard users with high visibility and sensitive information from targeted online attacks” (Google Advanced Protection Program) — journalists, activists, election workers, people at risk of targeted attacks. It requires signing in with a passkey or physical security key rather than a password alone, restricts which third-party apps can touch your account data, and applies stronger checks on suspicious downloads and account recovery (Google Account Help).
The trade-off is real: recovery gets stricter, most third-party apps that request “high-risk” account access get blocked, and app passwords stop working entirely — Google states that “apps that use app passwords instead of 2-Step Verification are blocked for users with Advanced Protection,” and existing app passwords are revoked on enrollment (Google Account Help). If a controlling partner has iCloud access to a shared Apple ecosystem, Google separately warns that an iCloud backup containing your Google session data could let someone bypass Advanced Protection’s sign-in requirement on a new device (Google Account Help). Enroll at your Google Account’s Security section; add a recovery email and phone number and turn on 2-Step Verification first (Google Account Help).
Advanced Protection isn’t for everyone — it’s built for people at genuinely elevated risk, and its friction is a cost some people shouldn’t have to pay for ordinary use.
Layer 3: apps
Play Protect — and its honest limits
Google Play Protect scans apps at install and periodically afterward for harmful behavior, and it’s on by default (Google Play Help). Check it’s active at Play Store → profile icon → Play Protect → Settings → Scan apps with Play Protect.
A clean Play Protect scan is one data point, not proof of a clean phone — Locking down your Android covers independent testing on its real-world detection limits. Treat a clean scan accordingly and don’t stop there.
Permission manager
Android gives you two ways to audit permissions: per-app, or by permission type across every app. For a full sweep, go to Settings → Security & Privacy → Privacy → Permission manager, tap a permission type — Location, Camera, Microphone, Contacts, and more — and see every app that currently holds it (Google Android Help). For location specifically, Android offers All the time, Allow only while using the app, Ask every time, and Don’t allow — prefer “while using the app” unless an app has a genuine ongoing reason for background location (Google Android Help). If you’re unsure what a permission actually exposes, What app permissions actually mean breaks each one down.
Turn on automatic cleanup too: under Settings → Apps → [app] → Unused app settings, enabling Pause app activity if unused lets Android strip permissions from idle apps automatically (Google Android Help). You can also cut off camera and microphone access device-wide — Settings → Security & privacy → Privacy → Privacy controls, then turn off Camera access or Microphone access, which overrides any individual app’s permission (Google Android Help).
Sideloading and unknown sources
Apps installed outside the Play Store skip Google’s app-review process. Android controls this per-app: go to Settings → Apps → Special app access → Install unknown apps, and check which apps — a browser, a file manager — are currently allowed to install others, turning off any you don’t remember granting (Google Pixel Phone Help). The path can vary by manufacturer; search Settings for “Install unknown apps” if this doesn’t match your phone.
Starting with Android 13, Google also added “restricted settings”: some legitimate apps ask you to enable them for a specific purpose — Google’s example is an accessibility app that needs accessibility settings turned on — and a sideloaded app requesting one of these is blocked until you separately open that app’s settings and tap Allow restricted settings (Google Android Help). Google’s guidance is blunt: “we don’t recommend that you allow restricted settings unless you trust the app developer” — a request from an app you don’t remember installing is a signal to stop and think, not a routine prompt to clear (Google Android Help).
Accessibility services and device admin apps
These two settings deserve a slow, deliberate look, because both grant an app broad access to your screen or control over the device itself.
- Settings → Accessibility → Installed apps (or Downloaded apps). Legitimate accessibility services aren’t limited to screen readers — they also cover things like voice-control and switch-access tools — but if this list contains something you don’t remember installing for an accessibility need, that’s worth scrutiny before you decide whether to turn it off.
- Device admin apps — search Settings for the term, or check Settings → Security & Privacy → More security settings → Device admin apps. On most personal phones, expect none active.
If you find something you didn’t knowingly install in either list, stop before removing it — read Safety first, since disabling monitoring software can alert whoever installed it.
Layer 4: the device itself
Find Hub (formerly Find My Device) and its network
Google’s device-finding service is now called Find Hub. If you’ve added a Google Account to your device, it’s automatically turned on, and by default your device “stores encrypted recent locations with Google and participates in the Find Hub network, a crowdsourced network of Android devices that uses end-to-end encrypted location information to help Android users find their lost devices” (Google Android Help). To find, secure, or erase a lost device you need it powered on, connected, signed in, and visible on Google Play (Google Android Help).
From the Find Hub app you can play a sound, mark the device as lost (which locks it with your PIN and, on Android 17 and up with fingerprint or face unlock configured, can require both a PIN and biometric to get back in), or factory reset it remotely (Google Android Help). There’s also Remote Lock — you can lock a lost or stolen device’s screen using just its phone number, without signing in first, as long as Remote Lock is turned on and the device is online (Google Find My Device).
The same network also powers unknown tracker alerts: if an AirTag, a Find Hub-network tag, or a compatible tracker is traveling with you without its owner nearby, your phone can notify you, show its travel path on a map, and let you play a sound to locate it — without alerting the tracker’s owner that you did (Google Android Help). If you get this alert and can’t find the tracker, Google’s own guidance is to “go to a safe public location and contact law enforcement or a trusted contact if you feel that your safety is at risk” (Google Android Help).
Protect against unauthorized factory resets
Separately from Find Hub, Android has a device protection feature: if your phone has a Google Account and a screen lock, a factory reset (yours or an attacker’s) requires that account’s password or your old screen lock before anyone can set the phone up again — “only someone with your Google Account or screen lock could use it” after an unauthorized wipe (Google Android Help). This applies automatically once both conditions are met.
The lockdown option
Android has a purpose-built panic switch: Lockdown. Once enabled, it appears in your power menu (hold Power and Volume up together on most phones) and, when tapped, immediately “turns off notifications, fingerprint or face recognition unlocking, and Extend Unlock while on your lock screen” — from that point, only your PIN, pattern, or password will get back in (Google Android Help). It’s off by default: go to Settings → Display → Advanced → Lock screen display (or Security & location → Lock screen preferences on older versions) and turn on Show lockdown option (Google Android Help). It’s one-time-use — Google notes “lockdown will only work until you unlock your device” (Google Android Help) — so enable it before you need it: a moment where someone is pressuring you to unlock with your face or thumb is not the moment to be searching Settings.
Check for a work profile
If your phone shows a Work tab under Settings → Passwords and accounts, it has an Android Work Profile, a separation Google designed so “your organization manages your work apps and data while your personal apps, data, and usage remain private” (Google Work Help). Work apps show a briefcase icon. If your phone was ever set up by an employer, this matters — see What MDM profiles can see for what device management can and can’t reach.
Hide sensitive apps: Private Space
On Android 15 and up, on unmanaged personal devices, Private Space creates a separate, lockable area for apps you don’t want visible by default — “a digital safe within your phone for the apps you don’t want others to easily access or find” (Google Android Help). Set it up at Settings → Security & privacy → Private space. It can lock automatically every time the device locks, and its app-drawer container can itself be hidden — though Google is explicit it can’t be hidden from someone who connects your phone to a computer via Android Debug Bridge, or from device logs (Google Android Help). It isn’t available on organization-managed devices, devices with a supervised account, or devices with more than four users or profiles (Google Android Help).
Layer 5: the newer, stronger option — Advanced Protection as a device setting
Separate from the account-level Advanced Protection Program described above, newer Android releases add a device-level “Advanced Protection” setting under Settings → Security & Privacy → Advanced Protection (or Google → All services → Advanced Protection) (Google Android Help). This single switch turns on a bundle of hardening features at once; Google describes the design intent as “defense-in-depth” — once it’s on, the system “prevents accidental or malicious disablement of the individual security features under the Advanced Protection umbrella” (Google Android Help).
Turning it on requires a screen lock to already be set and may require a reboot. What it changes, per Google’s own list (Google Android Help):
- Play Protect can’t be turned off while Advanced Protection is active.
- Installs from unknown sources are blocked entirely — not just restricted — along with updates to apps that were originally sideloaded.
- Accessibility services are restricted to verified accessibility tools, closing off the broader accessibility access covered in the audit above.
- Theft Detection Lock, Offline Device Lock, and Inactivity Reboot add automatic locking if the device shows signs of theft, loses connectivity, or sits locked for 72 hours straight — inactivity reboot specifically “will make user data unreadable until a fresh unlock takes place.”
- USB Protection blocks unauthorized access over USB while locked, and 2G Network Protection blocks connections to older, less secure 2G networks on supported devices.
- Chrome gets stricter defaults: automatic HTTPS enforcement, JavaScript optimizer off, WebGPU disabled.
- An optional Intrusion Logging feature keeps end-to-end encrypted device logs for investigating a suspected compromise later (Google Android Help).
Turning it off reverses these settings and may itself require a reboot (Google Android Help). Availability depends on your Android version and manufacturer; if it isn’t in Security & Privacy, your phone likely hasn’t received it yet.
The trade-off mirrors the account-level program: real security gain, real friction. Blocking all sideloading will break any legitimate app you install outside the Play Store, and the accessibility restriction disables third-party accessibility tools not on Google’s verified list. Turn it on if you’re carrying real risk; know what you’re giving up if you do.
A last note on manufacturer variance
Every menu path in this guide is described for close-to-stock Android. Samsung, in particular, renames and relocates several of these: screen lock and biometrics live under Settings → Security and privacy, and Samsung’s own equivalent to Private Space is Secure Folder, an encrypted space with its own separate lock, auto-lock timing, and a “Lock and exit” shortcut (Samsung Support). A Samsung account isn’t required to use Secure Folder itself, but it powers the optional Reset with Samsung account recovery setting — skip it and you can’t recover Secure Folder if you forget its passcode — and its stronger “enhanced encryption” is opt-in, not the default state (Samsung Support). Samsung’s separate device-finder, Find My Mobile, requires Remote unlock to be “activated in order to use the Find My Mobile unlock feature” — worth turning on in advance if you want the option to reset a forgotten lock screen remotely (Samsung Support). If a setting here doesn’t match what you see, search Settings for the bolded term or check your manufacturer’s support site — the underlying protection usually exists, just under a different name.
None of this proves a phone is clean — no combination of toggles can promise certainty. The goal is closing the doors that get left open by default, one layer at a time.