Microsoft Edge Password Monitor compares saved credentials with known leaked credentials and alerts when a match appears. An alert means the password is no longer safe to keep using, not necessarily that someone has already signed in to that account. Reuse can turn one exposed password into several compromised services. The useful response is to change the affected site's password directly, review account activity and fix reused copies, rather than clicking a link from an unrelated email claiming to be the monitor.
Before you start
Open Edge settings yourself from the browser menu. Have access to your password manager and recovery email. Prioritize the email account, financial accounts and sites that can reset other services. Use a clean device if you suspect the current computer has malware.Do it step by step
- Navigate to Settings, Passwords and autofill, Microsoft Password Manager, Password security check. Confirm the affected website and username. Run a new check if needed; Microsoft documents this route for saved passwords.
- Open the service by typing its known address or using a trusted bookmark. Change the password there to a new, unique value. Do not merely edit Edge's saved entry while the old password remains valid on the service.
- Update the saved password in Edge or your chosen password manager after the service accepts the change. Test a fresh sign-in and turn on a second factor or passkey if the service offers a suitable method.
- Review recent sign-ins, recovery contacts and active sessions on the affected service. Sign out unknown devices. If money or data may have been accessed, follow that provider's incident and support process promptly.
- Search your own password manager for the same old password on other sites. Change each reused copy, starting with the most sensitive. Do not paste the password into an online 'breach checker' to look for matches.
- Return to Password security check to confirm the old saved credential is gone, then monitor for another alert. If the website no longer exists, remove the obsolete saved entry only after confirming it is not needed for account recovery.