A shared PC can retain a Steam session or a 'remember me' authorization. Closing the client window may not remove all persistent access, and a person with physical access could reopen it later. Steam Guard allows account holders to deauthorize previously authorized computers or devices; the next login then needs another Guard check. If the device was used by an untrusted person, also consider saved browser credentials and the linked email account.
Before you start
Use a trusted personal device. Check that the verified email address on Steam is still yours, and secure that mailbox with its own unique password and second factor. If you no longer have access to the email, recover it through its provider before making Steam security changes that may depend on mail.Do it step by step
- Open Steam Account Details and Manage Steam Guard or the device-management area. Review devices shown in the mobile authenticator if available. Note the device names and sign-in times before deauthorizing so you can distinguish your own laptop from the shared computer.
- Choose the option to deauthorize other computers or devices. Read whether it affects every remembered device, then proceed. Steam's Guard FAQ says a deauthorized computer will be treated as new on its next login and need a code.
- Change the Steam password if anyone may have seen or saved it. Use a unique value; do not reuse the mailbox password. Keep Steam Guard enabled and review whether email-based or mobile-app authorization best fits your recovery plan.
- On the shared computer, sign out of Steam and remove saved credentials from the browser or operating-system profile if you still have authorized access to that computer. Do not delete another person's browser data. If you cannot reach it, deauthorization and password rotation are the remote controls you own.
- Review account email, phone and recent trade activity. Cancel any unauthorized pending offers, and watch for new confirmations. If the device was used to browse a phishing site or install suspicious software, inspect the computer separately; account deauthorization does not remove malware.
- Test a sign-in on your personal device and complete the Guard prompt. Keep a recovery route available before retiring the old phone. Revisit the device list to ensure an unknown entry does not return.