Who Gets Into Your Accounts After You’re Gone?
There was a shelf in one of our storage rooms with several computers on it and a sticky note stuck to the front. A name and a date. The date was when the machine could be wiped and handed to somebody else. Until then, it sat there, powered off, waiting its turn. That sticky note was the closest thing the building had to a legacy contact. It worked.
This was how we handled people leaving or even passing away, and the occasional being fired. It was the process. As things got more cloud-based, we just locked accounts and let them sit.
At work, somebody had already decided
Over 23 years supporting a university department, I watched people leave the way people do. They took other jobs. They retired. Some of them, sadly, died. What surprised me was that the process was the same either way. We kept their digital work life for a period of time and passed on what the next person needed.
Human resources was notified. Anything that needed archiving was archived. If somebody took over that station, they got the files and the email with it. Otherwise, it was handled like any other departure.
The technology changed underneath it. The shelf with the sticky note became a checkbox. Once work moved into Google Drive and Box.com, we stopped thinking about hardware and started locking accounts instead, not deleting them, so nothing inside could change while somebody worked out what mattered. Email was handled the same way.
It was boring. That was the point.
Now notice what’s missing. Nobody needed a password. Not once. Access was arranged in advance, by whoever ran the system, according to a rule somebody had written down before anyone needed it.
A password list is not a plan
A friend of mine died recently. His wife had his passwords and his logins — all of them, written down, exactly the way the advice tells you to do it.
They worked fine for the day-to-day. Then things started locking.
She ended up needing a lawyer to get access through the companies that mattered, Apple and Google among them. And for months afterward, she kept finding accounts she hadn’t known existed. Bills that were set to auto-withdrawal, and there was no way to stop them because she did not know the login or password.
So why didn’t the passwords work?
Because a password gets you in, and that isn’t the same thing as being allowed in. Two-factor codes go to a phone that eventually gets shut off. You may not realize how many two-factor authentications you use on a daily or weekly basis, and if it’s sent to your smartphone, what happens if that is turned off or even lost? The smartphone two-factor authentication that most people use is the weakest one and most insecure.
Many companies’ Terms of Service generally state that an account isn’t transferable to anyone. And the moment a company learns the account holder has died, the question changes from “can you sign in” to “can you prove you’re entitled to this.” That’s a legal problem, not a technical one, and no notebook solves it.
She did everything the standard advice says to do. The standard advice is just incomplete.
Quick summary: Apple and Google each let you name someone in advance, in about ten minutes, using a setting already on your phone. Microsoft has no such option and will point your family toward a court order. Your password manager probably has an emergency-access feature you’ve never opened. Set the first two tonight.
Apple’s legacy contact takes about ten minutes
On an iPhone or iPad, go to Settings → your name → Sign-In & Security → Legacy Contact, then tap Add Legacy Contact. On a Mac, it’s the Apple menu → System Settings → your name → Sign-In & Security → Legacy Contact. You’ll need iOS 15.2 or later and two-factor turned on, which most accounts already have.
The person you name gets an access key. After you die, they need that key and a copy of your death certificate, and that’s the whole requirement. They don’t need an Apple device or an Apple Account of their own.
What they can reach: photos, messages, notes, files, and device backups. What they can’t is worth knowing in advance. Purchased movies, music, books, and subscriptions don’t transfer, and neither does anything in iCloud Keychain. Your passwords are specifically excluded from the feature designed to hand over your account.
Here’s the comparison that makes ten minutes worth spending. If you haven’t named a legacy contact, Apple’s own instructions tell your family to bring a court order, and it has to name them as the rightful inheritor of your personal information. Ten minutes now, or a probate lawyer later. Plus the money for the lawyer, consider that. Is that worth 10 minutes?
Google’s version runs on a timer
Google calls it Inactive Account Manager, and it runs on a different principle. Rather than waiting for a death certificate, it watches for silence.
You choose how long the account sits unused before the plan fires. You can name up to ten people and give each a different slice of your data. When the timer runs out, they get an email with a download link, and each verifies their identity by phone before anything is released.
Google measures inactivity based on sign-ins, account activity, Gmail use, and Android check-ins, so it’s hard to trigger by accident. Still, pick a window that a long trip or a hospital stay won’t set off.
There’s a default here that argues for setting it up at all. With no plan in place, Google reserves the right to delete an account and all its contents once it has been inactive across Google for at least two years.
Microsoft has no legacy contact, so your family gets a lawyer
Microsoft has no advanced option. No switch, no form, no person you can name in advance. If your family needs access to the account without the credentials, Microsoft’s own support page says the company requires a subpoena or court order, then adds that providing one still “does not guarantee that we will be able to assist you.” Germany and China are handled differently. The United States is not.
Meanwhile, two clocks run. A Microsoft account freezes after about a year of inactivity, and it’s deleted after roughly two years.
That’s the reverse of what we did at the university, and the contrast is the whole lesson. We locked accounts so nothing could change while people worked out what mattered. Microsoft’s clock isn’t preserving anything for anyone. It’s clearing space.
So the move is different here. Take stock of what actually lives in that account, especially if it holds the email address your other accounts reset to. Then move what matters somewhere with a real handover option.
The account your legacy contact can’t open
Your password manager is the master key to everything else, and most of the good ones have an emergency-access feature almost nobody turns on.
Bitwarden’s version shows the shape. You name a trusted contact and set a waiting period. If they request access, you can decline. If you don’t respond before the clock runs out, access opens automatically. You choose whether they can view the vault or take it over outright. It’s a paid feature rather than a free one, which is worth knowing before you count on it. If you’re not using a password manager yet, password managers explained covers why its the first move rather than the last.
The problem my friend’s wife actually hit wasn’t passwords at all. She didn’t know what existed. Months of finding accounts one at a time, usually because something charged a card.
Write down what exists, not what gets you in. A plain list of accounts, which ones bill monthly, and which email address each resets to is worth more to your family than every password you own, and it doesn’t need to be stored like a secret, because it isn’t one.
What I’d do, what I’d skip
What I’d do: set up both. I’ve named a legacy contact on my Apple account and configured Inactive Account Manager on my Google account, and I recommend it about as strongly as I recommend anything on this site. Ten minutes each, no cost, and it’s the rare piece of security advice that makes life easier rather than harder. Name the same person for both. Then tell them. An access key nobody knows they have isn’t much better than no access key.
What I’d skip: relying on the notebook by itself. Keep it if you like, somewhere sensible. Just understand that it’s a convenience for the living, and the day it’s needed most is the day it stops working.
Your situation may differ, and how estates are handled varies by state. For anything involving real money or real complexity, verify with an attorney rather than a blog post.
Think of who and what you want passed on, and consider also what you don’t want others to see after you leave, or hopefully not pass away without warning.
Verified Resources & Documentation
- Apple: Add a Legacy Contact for your Apple Account
- Apple: Request access to a deceased family member’s Apple Account
- Google: About Inactive Account Manager
- Google: Submit a request regarding a deceased user’s account
- Microsoft: Accessing Outlook.com, OneDrive, and other Microsoft services when someone has died
- Bitwarden: Emergency Access
Keep reading
- the two-factor authentication most people use is the weakest one
- password managers explained
- a one-hour digital declutter for the new year
If somebody in your life knew where to start, you’re already ahead of most families. If you’re not sure they would, it’s twenty minutes of work — ten for Apple, ten for Google — and it’s the only errand on your list that only counts if you do it first.
No one likes to talk about death or just leaving, but it happens. Do think about this.