Edge Password Monitor checks saved username-password combinations against known leaked credentials and can show unsafe entries in Password security check. The warning is actionable even if the original leak happened years ago or on another service. It does not mean Microsoft Edge leaked the password, nor does it prove the named account was used by an attacker. Rotate the credential on the actual service first, then repair any reuse.
Before you start
Use a device and browser you trust. If your Microsoft or work account syncs browser passwords, ensure you are in the expected Edge profile before opening the password manager. Have a way to receive any sign-in code from the service. Do not paste a leaked password into third-party checker sites.Do it step by step
- Open Edge Settings, Passwords and autofill, Microsoft Password Manager, then Password security check. Microsoft also documents a direct settings address. Review the listed account and the saved website before acting.
- Navigate to the service using a known bookmark or manually confirmed address. Sign in and inspect recent activity and recovery settings. If the site itself warns of unauthorized access, follow its incident process as well as changing the password.
- Generate a new, unique password and change it on the service. Confirm that the service accepted it before replacing the old value in Edge. Otherwise the browser may hold a password that does not match the account.
- Sign in once with the new password in a fresh session. Revoke unfamiliar sessions or app access where the service offers that control, and turn on its strongest practical sign-in protection.
- Find any other accounts using the old password and rotate each of them. A leak can be exploited on unrelated sites through credential stuffing even if the originally breached site is no longer used.
- Run Password security check again after the saved item updates and sync completes. Do not move an unresolved item to Ignore just to clear the badge; investigate a persistent match.