Who this is for: Page owners, advertisers, creators, and brand admins who need a reliable routine to make sure there’s no hacker inside the account and to lock it down against threats inside and outside Facebook/Meta.
How to use this guide: Go section by section. For each check you’ll see Where to find it in Facebook, What to verify, and What to do (the exact actions to take).
Before you start - two quick rules
Use a clean, trusted device and network. If possible, run a malware scan and use a private network (not public Wi-Fi) while doing these steps.
Have your password manager ready. You’ll rotate secrets and store backup codes securely.
Logins - Sign out everywhere & audit sessions
Where in Facebook:
Profile menu ▸ Settings & privacy ▸ Settings ▸ Accounts Center ▸ Password and security ▸ Where you’re logged in (you may also see this under “Security and login”).
What to verify
No unfamiliar devices, browsers, or locations.
Only your current device should remain after you finish.
What to do
Click See all ▸ Log out of all sessions (or remove individually).
If you see any suspicious session, proceed to rotate your password (see Section 5) before continuing the rest.
Business Accounts (Meta Business Suite / Business Manager)
Where in Meta:
Go to business.facebook.com ▸ Settings (or Business settings). Review these areas:
People & Partners (who has access, including external agencies)
System Users / Apps (service accounts and app access)
Assets (Pages, Ad accounts, Pixels, Catalogs) and Ownership
Security Center ▸ 2FA enforcement & Business verification
What to verify
Only expected People and Partners with correct roles; no unknown emails.
Ownership of key assets (Pages/Ad accounts) sits with the correct Business.
2FA is required for everyone in the Business (not just optional).
What to do
Remove unknown people/partners; downgrade over-privileged roles to least privilege.
In Security Center, Require two-factor authentication for all people with Business access.
Review System Users and Apps; remove anything you don’t recognize.
Confirm Business verification is in good standing to avoid takeover via compliance gaps.
Pages — Access & ownership
Where in Facebook:
List ALL your Pages: Left sidebar Menu → Pages → Your Pages (scroll the full list).
Alt: Top-right profile photo → Switch profile → See all Pages.Per Page (verify access): Open the Page → Settings (left) → Page Setup → Page access (New Page Experience shows “Page access” directly under Settings).
Business inventory: business.facebook.com → Business settings → Accounts → Pages (see Owned by and Partners; click a Page to view assigned People/Partners).
What to verify
New/unknown Pages: Anything you don’t recognize in Your Pages or Business settings → Accounts → Pages (check Owned by/Partners, and recently added entries).
People with Facebook access: Everyone is known; roles match their job; 2FA enforced at Business level.
Partners with access: Only expected partner Businesses.
Ownership/linking: Page is owned by your Business and correctly shown under Professional dashboard → Linked Business assets.
What to do
If an unknown Page appears:
Business settings → Accounts → Pages → select Page → Remove from Business (or remove the Partner who added it).
On the Page: Settings → Page Setup → Page access → Your access → Remove (if you were added directly).
If suspicious, report via Help & support → Report a problem, then continue hardening (log out sessions, enforce 2FA, rotate password, clear trusted devices, refresh backup codes).
Remove unknown people/partners; downgrade any over-privileged roles to least privilege.
If ownership is wrong, transfer Page ownership back to your Business.
Repeat these checks for every Page in your list, not just the main one.
Two-Factor Authentication (2FA) - Turn on & enforce
Where in Facebook:
Profile menu ▸ Settings & privacy ▸ Settings ▸ Accounts Center ▸ Password and security ▸ Two-factor authentication.
For Business: Business settings ▸ Security Center ▸ Two-factor authentication.
What to verify
2FA is ON for your account.
You have at least one strong method: Authenticator App or Passkey (prefer these over SMS).
Business-level setting requires 2FA for everyone with Business access.
What to do
Turn on 2FA and choose Authenticator App first; keep SMS only as a backup.
In Business settings, toggle Require 2FA for all people with access.
Save Recovery/Backup codes (see Section 9).
Password Rotation - Revoke access by changing the password
Where in Facebook:
Accounts Center ▸ Password and security ▸ Login & recovery ▸ Change password.
What to verify
The new password is unique, long, and stored in a password manager.
Saved login info and Remembered devices are cleared (see Section 8).
What to do
Change your password now if you saw any suspicious logins — do this before anything else.
After changing, log out of all sessions again (Section 1) to invalidate stolen cookies.
Update the password anywhere you used it (do not reuse across services).
Make sure the checkmark on ‘Log out of other devices’ is selected to ensure you are logging out of all other sessions.
Tips for a safe password
Create a password with at least 15 characters.
Use a mix of special characters, numbers, uppercase, and lowercase letters.
Do not reuse passwords from other platforms or services.
Security Notifications - Get alerts for unusual logins
Where in Facebook:
Accounts Center ▸ Password and security ▸ Alerts (or “Get alerts about unrecognized logins”).
What to verify
Alerts are enabled to your email and Facebook notifications (and Messenger if desired).
Your primary email and phone number are current and accessible.
What to do
Toggle alerts ON for email and notifications.
Go to Personal details to confirm your email and phone; remove any you don’t recognize.
Make sure the fields under ‘Pages you manage’, ‘Other notifications’, ‘Reminders’, and ‘More activity about you’ are selected. Also make sure you activated all notifications under ‘Where you receive notifications’. Ensure that all toggles for email and SMS are turned on so you receive ALL alerts.
Passkeys - Review or add
Where in Facebook:
Accounts Center ▸ Password and security ▸ Passkeys.
What to verify
Only your device(s) are listed as passkeys; nothing unfamiliar.
What to do
Remove any passkey you don’t recognize.
Consider adding a passkey on your primary device for phishing-resistant login.
Trusted/Saved devices - Clean the list
Where in Facebook:
Accounts Center ▸ Password and security ▸ Two-factor authentication ▸ Authorized logins (or “Saved devices” / “Trusted devices”).
What to verify
No devices are permanently trusted unless necessary.
What to do
Remove all trusted/saved devices. Only re-trust your primary device later if needed.
Backup (Recovery) Codes - Refresh and store securely
Where in Facebook:
Accounts Center ▸ Password and security ▸ Two-factor authentication ▸ Recovery codes.
What to verify
You have a fresh set of codes stored in a secure place (e.g., password manager secure notes).
What to do
Generate new codes; store them securely (never screenshot to your camera roll).
Label with date and share with no one. Treat them like keys to your account.
Copy the backup codes and paste them into the Spikerz Employee Protection feature after you generate the new codes.
Login alerts - Accounts Center
Where in Facebook:
Profile photo → Settings & privacy → Settings → Accounts Center → Password and security → Security checks → Login alerts.
What to verify
Email and Facebook notifications toggles are ON.
Contact info (Accounts Center → Personal details → Contact info) is correct.
(Optional) In Security checks, glance at Where you’re logged in and Recent emails to confirm activity looks legit.
What to do
Open Login alerts → turn Email + Notifications ON.
If you ever get an alert you don’t recognize: Log out all sessions → Change password → Turn on/confirm 2FA → Clear trusted devices → Refresh backup codes.
Connected apps & logins with Facebook
Where in Facebook:
Settings & privacy ▸ Settings ▸ Apps and websites (also check Business integrations in Business settings).
What to verify
Only trusted third-party apps/websites remain connected.
No unknown apps have manage pages, ads, or business permissions.
What to do
Remove any unused or suspicious integrations.
Re-authorize only what you need with the minimal scopes.
Tip: Make this a quarterly routine (set a recurring reminder) and require it for anyone who has access to your Pages or Business assets.






















