Skip to content
MDA-069 Mobile Devices & Apps

What are linked or trusted devices?

Linked or trusted devices are devices recognised by an account or service as authorised to access it.

What this means

They may include phones, tablets, laptops, smartwatches, browsers, vehicles or other connected systems.

A trusted device may receive security prompts, verification codes, notifications or account data.

It may also allow sign-in without repeating the full authentication process.

This matters because the account may be used from several devices.

Activity seen on one handset may have originated from another trusted device and then synchronised.

A trusted-device list can help identify the wider account environment.

It may show device names, models, last activity, approximate location or account-link dates, depending on the provider.

But labels are not always reliable.

A device name may be chosen by the user, duplicated or left unchanged after ownership changes.

A trusted device may also remain listed after it is sold, lost or no longer used.

That may alert users, change security state or alter evidence.

Where lawful and appropriate, preserve the account records before changes occur.

The operational takeaway is: linked and trusted devices show which systems may access or influence the account. Map them carefully because they may explain synchronised activity, alternative access and the wider attribution picture.

What to check or do next

  • Investigators should compare trusted-device records with physical devices, identifiers, login history, IP records and possession.
  • Do not remove devices from the account or revoke access informally.
Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.