Before the old phone leaves: the account side
Most people factory-reset a phone before selling or handing it on. Nothing wrong with that — it just only handles the device side. The account side still holds plenty: that handset’s login sessions may still be valid, it may still sit on some services’ trusted-device lists, and any authenticator entries bound to it vanish the moment you wipe — and that last one hurts you, not the next owner.
Two sides, and only one of them gets wiped
A factory reset erases data on that handset. It does not travel out to each service’s back end and delete the record saying “this device signed in”.
So there are two checklists: the device side (erase, sign out of the system account, remove the SIM) and the account side (end sessions, remove from trusted devices, move authenticators off). Doing one leaves a tail.
Order matters too: the account side comes before the wipe. The practical reason is that once the handset is erased, the authenticator entries bound to it are gone — and then the very thing you need in order to sign in and remove the device is missing. So before starting, spend ten seconds on one question: apart from this handset, do you have any other way into that authenticator — a second device, an exported backup, the recovery codes you saved at setup? If the answer is no, fix that first. Done in the wrong order, this one is hard to walk back.
Apple’s own ordering makes the point
Apple’s “before you sell, give away, or trade in” page lays the sequence out plainly: back up, unpair an Apple Watch, sign out of iCloud / iTunes / App Store, deregister iMessage if you are moving to a non-Apple phone, then “Erase All Content and Settings”, and finally remove the device from your trusted-device list.
Note where the erase sits — after signing out, before the trusted-device cleanup. That ordering is not arbitrary: unbind at the account level while the device still works, so the wipe does not take the route you need along with it. Android menus sit in different places and go by different names, and this article did not check them vendor by vendor. So the checklists below are written as states to reach rather than buttons to press.
The account-side checklist
Ordered by how much it hurts to skip, not by operation order:
- Move the authenticator entries off first. This is the one that bites. Set 2FA up on the new device and confirm it produces working codes before wiping anything. Do not lean on “I have backup codes” without first confirming you can actually find them. Moving 2FA to a new phone is the long version.
- End all sessions. Services name it differently — device management, logged-in devices, active sessions — but it does the same job: invalidate whatever login state is still sitting on that handset.
- Remove it from trusted-device lists. Some accounts treat “this device” as a credential that skips a verification step. Wiping the phone does not delete that record.
- Check what else is pinned to it — a number receiving SMS codes, or a push-approval device.
The security check-up has a devices-and-sessions section you can tick through.
The device-side checklist
- Sign out of the system account (iCloud, Google account). Wiping without signing out can leave activation-lock style problems — awkward for whoever gets the phone, and for you.
- Take out the physical SIM; handle an eSIM per your carrier’s instructions. Leaving the number in the handset hands over the SMS-code entry point with it.
- Erase all content and settings rather than deleting apps one by one. Deleting an app is not deleting its data.
- Power it on once afterwards and confirm it actually sits at the setup screen instead of still inside your account.
If the phone is already gone
Sold, given away or lost before you thought about this? Then the order inverts, and the work splits into two lines that do not carry the same certainty.
The account side needs nothing from that phone and can be finished right now. End all sessions, remove the device from trusted lists, then check whether any account’s security settings have been changed. If an authenticator was bound to that device and you have no backup, use the account’s official recovery path rather than repeatedly guessing yourself into a lockout. The full stolen-account sequence is in the first ten minutes after an account is compromised.
The device side depends on conditions that were set before you lost it. Apple’s help page has a separate branch for a device you no longer have, and each item there carries a precondition:
- Erase it remotely from Find Devices on iCloud.com. Only works if Find My was switched on beforehand and the device can still reach the network. Miss either and the command simply queues, possibly forever.
- Change your Apple Account password and confirm two-factor is still on. This removes nothing already sitting on the handset, but it stops the new holder using your iCloud — and stops them deleting what is in it.
- Take it off your trusted device list so it can no longer receive codes.
- Deregister iMessage if you moved to a non-Apple phone, or texts sent to you may keep disappearing into it.
- Remove the cards from Wallet.
- Cancel or transfer AppleCare and similar plans.
Do the account side first: it has no preconditions and takes effect the moment you finish it. Then attempt the device side. If the phone went to a specific person, asking them to erase it themselves is often faster than waiting on a remote command.
The point of this section is short: once the device is out of your hands, the account side is all you still control — so do that side thoroughly.
Common questions
I already factory-reset it. Is there anything left to do in my accounts?
Yes. The reset erased data on that handset; it did not remove the back-end records saying that device signed in or that it is trusted. At minimum, end all sessions and remove the device from trusted-device lists.
Wipe first or handle accounts first?
Accounts first. Apple’s help page also puts signing out of iCloud / iTunes / App Store before “Erase All Content and Settings”. The practical reason is sharper: once the authenticator bound to that handset is erased, you may not be able to sign in to remove the device at all.
The phone is already sold. Too late?
The account side needs nothing from that phone and can be finished right now, and it should be: end all sessions, remove it from trusted devices, check whether security settings were changed. The device side depends on conditions set earlier — remote erase from Find Devices on iCloud.com only works if Find My was on and the handset can still reach the network. Beyond that, change your Apple Account password, deregister iMessage if you moved to a non-Apple phone, and remove the cards from Wallet. If an authenticator lived on that device with no backup, use the official recovery path instead of guessing yourself into a lockout.
Sources
- Apple Support · What to do before you sell, give away, or trade in your iPhone or iPad — the order it gives is back up, unpair Apple Watch, sign out of iCloud / iTunes / App Store, deregister iMessage if moving to a non-Apple phone, then “Erase All Content and Settings”, and finally remove the device from your trusted-device list (checked 2026-09-04)
- Android erase and sign-out paths differ by manufacturer, and eSIM handling follows your carrier’s instructions; no menu paths are given here.