Skip to content
FDownloader

Guide

How to change your Facebook password

Changing a Facebook password on desktop and mobile, what to do when you cannot remember the old one, and how to end other sessions afterwards.

Last updated · Published by FDownloader

All guides

A Facebook login is seldom only a Facebook login. The same secret opens Messenger, it frequently opens whatever else you signed into using Facebook, and behind it sit years of photographs and private conversations. Replacing it takes two minutes. What gets skipped is everything that has to happen in the minutes after, which is where the protection actually comes from.

When a change is worth making

Treat this as a response to something, not as housekeeping.

  • Activity you cannot place. A session from a city you have never visited, a post you did not write, a message sent while you slept.
  • The same secret in use elsewhere. If it also opens your email or a shopping account, one leak anywhere makes it worthless everywhere.
  • You typed it somewhere you should not have. A page reached from a direct message, a login screen that looked almost right, a computer belonging to somebody else.
  • Another person knows it. A former partner, a colleague who used to run the Page, a relative who set the account up for you.
  • A breach notice naming your address. Browsers and managers increasingly surface these; replace anything sharing the exposed value.

Absent from that list is the calendar. Rotating a working password every ninety days was orthodox for a decade, and the bodies that issued that advice have withdrawn it. NIST tells services not to impose scheduled changes, and the NCSC published its reasoning: people obliged to invent a fresh secret each quarter produce a predictable series, note it somewhere convenient and reuse it. A strong password left in place, changed the moment there is a reason, beats that comfortably.

The change itself

  1. Open the password setting. From Settings, work towards the Accounts Centre and then Password and security. Aim for those names rather than a fixed run of clicks, because Meta relocates this screen between releases.
  2. Enter the password you have now. That request is the point rather than an obstacle: it separates somebody who knows the secret from somebody who found the device unlocked.
  3. Type a long replacement, twice. Switch the reveal control on. One mistyped character in a masked field locks people out of the account they were protecting.
  4. Decide what happens to other devices. Where Facebook offers to sign your remaining sessions out alongside the change, take the offer. Anything left signed in keeps its existing access.
  5. Save, then update wherever it was stored. A browser or manager holding the previous value will keep presenting it and keep failing. Edit that entry now, not at the third rejected login.

Where the setting lives on the web

The control belongs to your account rather than your profile, so it is reached through Settings from the account menu, not through anything on your timeline. Wording and nesting differ between versions, which is why the route above stops short of naming every click. If a search result hands you a precise sequence and one of its steps is missing, the sequence is stale rather than your account being unusual.

Where it lives in the app

Same destination, different journey, beginning from the menu behind your profile picture. The app has been rearranged more often than the website, so scan the security grouping rather than following a recipe from any page, this one included.

One thing to know first: the Accounts Centre is Meta-wide. If your Facebook profile is grouped with an Instagram profile, the screen may list more than one, and you are editing whichever you select. Where linked profiles share a single login, one change moves both.

When you cannot remember the current one

The change form is the wrong door, since it keeps asking for something you do not have. Use the forgotten-password link on the login screen; Facebook's recovery entry point also sits at facebook.com/login/identify, where an email address, a mobile number or a username locates the account.

Recovery then depends on something you can still reach, because Facebook sends a code or a link to a contact route already held on the account. Where none survives, the flow may offer an identity check instead — slower, and varying by country. That sluggishness is a feature: a path quick enough to satisfy you is quick enough for somebody pretending to be you.

Two rules for this stage. Begin it yourself, from hardware you own, because a reset carried out on a borrowed computer hands the new password to whatever is watching that machine. And never start from a reset message you did not request: an unrequested one is among the oldest phishing shapes in circulation, and the answer is to ignore it and reach Facebook under your own steam.

What makes the replacement strong

Length does nearly all of the work. NIST's current revision tells services to set their floor well above the traditional eight characters, around fifteen, to accept much longer inputs without quietly truncating them, and to stop demanding a mixture of character classes. Those mixture rules went because the results were guessable: told to include a digit, people append 1.

  • Several unrelated words. Four that would never appear together in a sentence give real length and survive being typed on a phone keyboard, which a dense scramble does not.
  • Better, something generated. A manager produces twenty characters of noise and remembers them, so the length costs you nothing.
  • Used nowhere else. Reuse is the mechanism behind credential stuffing, where pairs leaked from one site are replayed against every large service automatically.
  • Nothing lifted from your own profile. Pets, birthdays, teams, a partner's name: all published on the very account it defends.
  • Not last year's with a new digit. Incrementing a previous value is the first transformation guessing tools apply.

The first few minutes afterwards

A new password evicts nobody by itself, so the following matters more than the change did:

  • End the other sessions. The security section lists where the account is signed in. If that list is long and strange, log out of all of it and sign back in yourself.
  • Confirm the login-alerts setting. Facebook can notify you about logins it does not recognise, and that notice is the earliest warning of a further attempt.
  • Sign in again on your own hardware. Phone, tablet, a television app, Messenger. Devices holding the old value fail silently, and a handset that stopped showing notifications is often a lapsed login.
  • Correct the stored copy. Whatever remembers it for you needs the new value, and duplicates want deleting. The companion piece on where a Facebook password can be kept covers the differences between those stores.
  • Audit the recovery details if you suspect intrusion. Somebody who was inside may have added their own address or number, and that addition outlives every password change you make.

Questions that come up afterwards

Will Facebook tell me it changed?

Meta notifies the address on the account, and that email is how many people learn an account has been taken. If one arrives unexpectedly, start recovery directly rather than following links inside the message.

Does changing it sign me out everywhere?

Not on its own and not dependably. Facebook may present a choice about your other sessions; if you clicked past it, close them manually. Assume nothing was evicted until you have read the list.

Can I go back to one I used before?

Facebook may reject a value it has seen on the account before, and no rule about how far back it checks is published. Either way, an old password may already sit in a leaked dataset.

How long should the new one be?

Longer than the eight characters many services still accept as their floor. Fifteen upwards is where current guidance points, and something in the twenties costs nothing once a manager does the remembering.

Why has the reset code not arrived?

Check the spam folder, then check whether the address or number held on the account is still one you can open. A lapsed work address explains most of these, and requesting several codes in quick succession tends to slow things down.

Is a new password enough after an account has been taken?

No. Whoever had access may have added a login method, a recovery contact, an admin role on a Page or an app authorisation, and none of that falls away with the old password.

A short job wrapped inside a slightly longer one, then. Make the replacement long and unique, hand the remembering to software built for it, and spend the extra minutes on sessions, alerts and recovery contacts. Those minutes decide whether the change accomplished anything.

Sources