Skip to content
All guides

Password Managers

Why Is My Password Manager Asking for a New Device Approval?

A new device approval may be legitimate if you are signing in, but unexpected prompts can indicate phishing or attempted access. This guide explains how to verify the request and secure your password manager account.

By the 4safer teamUpdated August 29, 20268 minutes read

Approve only sign-ins you started

If your password manager asks for a new device approval, approve it only if you personally started that sign-in on a device you control. If the request appears unexpectedly, deny it, open the password manager through the official app or website, and review account activity.

A password manager protects many accounts, so new device requests deserve more caution than ordinary app notifications. Do not share approval codes or recovery codes with anyone.

The request may be legitimate after a new phone, browser, computer, reinstall, or travel. It may also be a sign that someone has your email, master password, or session information.

Why new device approval exists

New device approval is meant to prevent a password alone from being enough to access your vault. It may use email confirmation, MFA, trusted devices, recovery keys, or provider-specific approval flows.

That protection works only if you refuse requests you did not initiate. Scammers may call, text, or email pretending to be support and ask you to approve a request or read a code.

CISA recommends MFA because additional verification reduces password-only risk. But MFA prompts must be treated carefully.

  • New phone setup.
  • New browser profile.
  • App reinstall.
  • Travel or VPN.
  • Suspicious login attempt.
  • Phishing attempt asking for approval.

Verify without clicking alert links

Open the password manager directly. Review devices, sessions, recent activity, trusted devices, email address, MFA methods, emergency access, and recovery settings.

If you received the request by email, avoid using the email link as your first path. Phishing emails can imitate device approval prompts.

If the request was yours

Confirm that the device is yours, updated, and protected by a screen lock. Approve the device only through the official password manager flow.

After approval, check whether old devices should be removed.

If the request was not yours

Deny the request, change the master password from a trusted device, enable or reset MFA, and sign out unknown sessions. Then review email security because password manager approvals often depend on email.

If you reused the master password anywhere, replace it everywhere.

  • Deny the prompt.
  • Change the master password.
  • Enable MFA.
  • Remove unknown sessions.
  • Check recovery settings.
  • Secure your email account.

Check for exposure signals

Check whether the email tied to the password manager appears in known exposure data. A match does not prove vault access, but it can explain targeting.

Never enter the master password into an exposure checker.

Review high-value accounts

If you believe the password manager account may have been accessed, prioritize email, banking, payments, cloud storage, phone carrier, work tools, and social media.

Change critical passwords from a trusted device and enable MFA.

Reduce approval fatigue

Unexpected prompts are easier to judge when you keep a small list of trusted devices and remove old ones. Do not leave password manager sessions active on shared computers.

Treat every approval as a login decision, not a nuisance.

Frequently asked questions

Should I approve a device request I did not start?

No. Deny it and review your password manager account from the official app or site.

Does a new device request mean my vault was opened?

Not necessarily. It may show an attempted sign-in or normal setup. Verify account activity.

Should I change my master password?

Yes if the request was unexpected, if the password was reused, or if account activity looks suspicious.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.