Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

ChatGPT Account Security: See Who Is Signed In and Log Them Out

Portrait of Antonio Pazzi, president of OKTO Solutions

By ·

President of OKTO Solutions · 6 minute read

Since June 2, 2026, ChatGPT lets you see every device signed in to your account under Settings, Security, Active sessions, and close the ones you do not recognize. A Lockdown Mode added on June 4 limits web and external tool access to cut the risk of data leaving a conversation. Both settings are worth checking today.

Millions of people open ChatGPT every day, but very few can answer a simple question: who else is signed in to my account right now? Until recently there was no easy way to check. That is changing.

In June 2026, OpenAI rolled out two new security options in ChatGPT. The first, called Active sessions, shows you every device connected to your account and lets you disconnect the ones you do not recognize. The second, Lockdown Mode, reduces the risk of data leaking when you work with sensitive information. Two quiet additions that matter as much to the public as to the small businesses in Trois-Rivières and the Mauricie that use AI every day.

Quick answer: Since June 2, 2026, ChatGPT lets you review the list of devices connected to your account (Settings, Security, Active sessions) and remotely close the suspicious ones. A Lockdown Mode, added on June 4, limits access to the web and to external tools to reduce data theft. For a small business, both settings are worth checking right away.

1. What did ChatGPT just add?

The most useful addition day to day is called Active sessions. It works like the security page you may already know from Microsoft 365 or from your bank: a list of every place your account is open. For each session, ChatGPT shows the device type, the app being used, an approximate location, the sign-in time, and whether the device is marked as trusted.

In practice, you can:

  • See at a glance every device connected to your account;
  • Spot a connection that does not look like you (an unfamiliar device or city);
  • Close one specific session, or every session at once, including the one you are using right now.

A few limits to know about. Closing every session can take up to 30 minutes to take effect everywhere. The feature covers direct connections to ChatGPT, but not third-party app sessions or the Codex command line tool. And according to OpenAI, it is not offered on accounts tied to an organization’s single sign-on (SAML or OIDC), where your IT department manages access instead.

Above all, keep in mind that this is not an alarm. ChatGPT will not warn you the moment somebody signs in. It is up to you to look. That is why it pays to make it a habit, the same way you check who is on the office Wi-Fi.

Compromised online account on a small business screen

2. Why does this matter for your Quebec business?

A ChatGPT account is no longer a novelty. Plenty of employees paste client emails, tender documents, pieces of contracts or financial data into it to save time. If that account is shared, left open on an old laptop or protected by a password reused elsewhere, it becomes a doorway into company information.

The most common danger is not a sophisticated hack. It is far more ordinary: a password stolen in some other site’s breach, a session left open on a shared computer, or a former employee who still has access. The Active sessions page finally gives you a simple way to close those doors without changing your password over and over.

For a business in the Mauricie or the Quebec City area, the winning habits come down to a few rules:

  • Every employee has their own account, never a shared one;
  • Two-factor authentication is turned on everywhere it is available;
  • Someone is responsible for removing access when an employee leaves;
  • AI tools are governed by a clear policy on what may be put into them.

That is exactly the kind of digital hygiene we set up with our clients. If you have no clear picture of who uses what in your company, our managed IT services include that access cleanup and the practices that fit how you actually work.

3. How do you check your active sessions in one minute?

The steps are quick, on a computer or in the mobile app:

  1. Open ChatGPT and go to Settings;
  2. Click the Security section;
  3. Open Active sessions;
  4. Go through the list of devices, apps and locations shown;
  5. If an entry is unfamiliar, disconnect it. If you have any doubt, disconnect every session and change your password.

While you are there, turn on two-factor authentication if it is not already active. It is the single measure that blocks the large majority of unauthorized access, even when your password has leaked elsewhere.

Monitoring sign-ins and security threats

4. Lockdown Mode against data leaks

The second addition targets more sensitive work. Lockdown Mode, which arrived on June 4, 2026 for personal accounts and self-serve ChatGPT Business accounts, is an option you turn on when you handle confidential information.

Once active, it cuts or limits several features that connect ChatGPT to the web and to outside services: live web access, Agent mode, deep research, live connectors, file uploads and some image features. The goal is to reduce the paths through which a prompt injection attack could push your data out of the conversation.

What does that mean? A prompt injection is booby-trapped text hidden in a web page, a PDF or a document the AI reads, which quietly tries to give it orders, for example to export your information to an outside server. By locking the exits toward the web and external tools, ChatGPT removes most of those escape routes.

One important nuance, flagged by OpenAI itself: the mode does not block the booby-trapped text from arriving, it mainly blocks the ability to send your data out. So it is not total protection, but it is a real reduction in risk. For AI agents that automatically read outside content, this kind of attack is precisely what worries security specialists this year.

Artificial intelligence and security at OKTO Solutions

5. Three security habits to adopt now

Beyond those two options, here is what we recommend to clients bringing AI into their operations:

  • Check your active sessions once a month. Five minutes per account, and you spot any abnormal access before it does damage.
  • Turn on Lockdown Mode for sensitive work. If you are working on confidential files or client data, the setting is worth the detour.
  • Frame AI usage with a simple policy. Spell out what may be put into an AI tool, who is allowed to use it and with which account. That is often the missing link in a small business.

None of this calls for buying new software. It calls for discipline and a bit of guidance. The same holds for ChatGPT, Microsoft Copilot, Google Gemini or any other AI tool your team adopts.

Frequently asked questions

How do I know who is signed in to my ChatGPT account?

Go to Settings, then Security, then Active sessions. You will see the list of devices, apps and approximate locations tied to your account, with the sign-in time. You can disconnect one specific session or every session at once.

Is ChatGPT Lockdown Mode useful for a small business?

Yes, especially if your employees handle confidential data in ChatGPT. It limits access to the web and to external tools to reduce the risk of an attack pushing your information out. It is not complete protection, but it is an extra layer worth turning on for sensitive work.

Should I still turn on two-factor authentication?

Absolutely. Checking active sessions helps you react after the fact, while two-factor authentication blocks access from the start, even if your password has leaked elsewhere. The two measures complement each other and should be active on all your important accounts.

Clean up your access with OKTO Solutions

These new ChatGPT options are a good reminder: security does not rest on a single tool, but on a series of good habits applied everywhere. If you want a clear picture of who has access to what in your business, and solid rules around AI, our managed IT services cover access management, two-factor authentication and the governance of digital tools. Contact our Trois-Rivières team to talk it over with no obligation.

Reading about AI is one thing. Connecting it to your own data is another: artificial intelligence in business, custom AI application development and our IT services in Quebec City.

A question on this subject, for your own company?

An article explains the principle. A twenty minute call tells you what it changes at your place, with your systems and your constraints.