What it means
Steam Guard can treat a previously authorized computer as recognized so it does not need the same new-device check every time. Deauthorizing removes that remembered status; the next login from the machine requires a Guard code. Changing the account password invalidates an exposed secret. Both can be needed after using a shared computer or seeing an unknown session, and neither secures a compromised email mailbox by itself.
A real-world example
Someone signs into Steam on a friend's laptop and checks Remember me. Months later they change their password but never inspect device authorization. Deauthorization is the explicit way to make that laptop face the new-device challenge again.
What to do
In Account Details, review Manage Steam Guard and authorized devices. Deauthorize devices you no longer trust, change the password if it may have been seen, and secure the linked email with a separate password and second factor. Review trades for actions already taken.
The distinction that matters
Steam's Guard FAQ says deauthorizing may apply to all computers or devices. That can sign you out of your own hardware, so keep your recovery route available before proceeding. Deauthorization does not remove malware, and changing the password does not retract items already transferred.
Steam Guard device behavior Steam security recommendations