The steps to change your Facebook password

Open Facebook and go to the menu in the top right corner — the downward arrow next to your profile picture. Click Settings and privacy, then Settings. On the left side, select Password and security. You'll see a section labeled Change password with an Edit button next to it. Click that button.

Facebook will ask you to enter your current password first, then type your new password twice to confirm it matches. Once you've entered both, click Change password at the bottom. Facebook will log you out of all your devices and sessions, and you'll need to log back in with your new password on each one.

The whole process takes about two minutes. If you can't remember your current password, don't use the change password option — instead, use the "Forgot password?" link on the Facebook login page, which will send you a recovery code to your email or phone number.

Key Takeaways

  • You change your password through Settings and privacy > Settings > Password and security > Edit, then enter your current password and your new one twice.
  • Changing your password logs you out everywhere, so you'll need to sign back in on your phone, computer, and any other devices you use Facebook on.
  • If you forget your current password, use the "Forgot password?" link on the login page instead of trying to change it from Settings.
  • A strong password uses a mix of uppercase and lowercase letters, numbers, and symbols, and is at least 12 characters long.
  • After you change your password, check your login activity in Settings to see if anyone else has accessed your account recently.

Why you might need to change your password

You should change your password if you've shared it with someone, used the same password on another website that got hacked, or notice login activity you don't recognize. If you suspect someone else has accessed your account, changing your password is one of the first steps to take back control.

Even if nothing has gone wrong, changing your password every few months is a reasonable security practice. Facebook doesn't require you to do this, but it reduces the window of time a stolen password could be used against you.

What makes a strong Facebook password

A strong password is long and uses different types of characters. Aim for at least 12 characters, mixing uppercase letters (A-Z), lowercase letters (a-z), numbers (0-9), and symbols (!@#$%^&*). Avoid passwords based on your name, birthday, or other information someone could guess or find on your profile.

Don't reuse the same password across multiple websites. If one site gets hacked, attackers will try that password on Facebook, email, banking, and other accounts. A password manager like Bitwarden, 1Password, or Dashlane can generate and store unique passwords for each site so you only have to remember one master password.

Checking your login activity after changing your password

After you change your password, it's worth checking whether anyone else has been accessing your account. Go to Settings and privacy > Settings > Password and security and scroll down to Where you're logged in. This shows every device and browser currently signed into your account.

If you see a device you don't recognize, click the three dots next to it and select Log out. You can also click Log out of all sessions except this one at the bottom to sign out everywhere at once and force yourself to log back in on each device with your new password.

What to do if you can't access your email or phone number

If you've lost access to the email address or phone number linked to your Facebook account, you won't be able to use the "Forgot password?" option to reset it. Instead, go to facebook.com/login/identify and enter your username, email, or phone number. Facebook will ask you to verify your identity using a photo ID or by answering security questions you set up earlier.

Once you've verified who you are, Facebook will let you regain access to your account and change your password. This process can take a few days, so be patient. If you set up a trusted contact in your security settings beforehand, that person can also help you regain access by confirming your identity.

Setting up two-factor authentication for extra security

Changing your password is important, but a second layer of security is even better. Two-factor authentication (also called two-step verification) requires you to enter a code from your phone or an authentication app every time you log in from a new device. Even if someone has your password, they can't access your account without that code.

To turn on two-factor authentication, go to Settings and privacy > Settings > Password and security and find Two-factor authentication. Click Edit and choose whether you want codes sent to your phone via text message, generated by an app like Google Authenticator or Microsoft Authenticator, or both. Facebook will walk you through the setup process.

Frequently Asked Questions

Will changing my password delete my messages or photos?

No. Changing your password only affects how you log in. All your messages, photos, posts, and other account data stay exactly as they are. The only thing that changes is that you'll need to use your new password to sign in.

How often should I change my Facebook password?

There's no set rule. If your account hasn't been compromised and you use a unique, strong password, changing it once or twice a year is reasonable. If you suspect someone has accessed your account or you've reused the password elsewhere, change it right away.

What happens to my other devices when I change my password?

You'll be logged out of Facebook on all your devices — your phone, tablet, computer, and any other place you were signed in. You'll need to log back in with your new password on each device. This is a security feature to make sure only you can access your account.

Can I see who tried to log into my account?

Yes. In Settings and privacy > Settings > Password and security, look for Where you're logged in. This shows all active sessions. You can also check Login alerts in the same section to see notifications of login attempts from new devices or locations.