How to Audit Which Devices Have Access to Your Home (2026 Guide)
I logged into my router's admin panel one Tuesday night expecting the usual dozen or so devices—phones, laptops, a smart TV, maybe the guest's tablet. What I found instead were thirty-seven connected gadgets, including a 'SmartBulb_Kitchen_2' that I had definitely returned to the store six months prior, and a mysterious 'ESP-32C' that turned out to be a neighbor's Bluetooth speaker that had somehow latched onto my 5GHz band. That night, I realized I had no real idea who—or what—had access to my home. This is the 2026 guide to changing that: a practical, first-hand walkthrough of auditing every device that can unlock your door, watch your living room, or listen to your conversations.
Why Auditing Your Home Device Access Matters in 2026
If you're like most people I talk to, you picked up a smart doorbell during the pandemic, added a few cameras when porch pirates got brazen, and maybe threw in a robot vacuum for good measure. By 2026, the average U.S. household has 22 connected devices, according to industry estimates—and that's not counting the ones you forgot about. The problem isn't the gadgets themselves; it's the permissions they carry. Each device is a potential entry point, and every app that talks to it is a vector for someone else to peek into your life.
I've seen it happen: a friend's smart lock was accessed by a former roommate who still had the app installed, because she never revoked his digital key. Another acquaintance found that her outdoor camera was streaming to a third-party analytics service she never consented to—buried in the fine print of a firmware update. These aren't edge cases; they're the norm when you don't audit. In 2026, with more devices than ever using Zigbee, Matter, and Thread protocols, the access map is sprawling. A single forgotten account on a voice assistant can let someone reorder groceries, unlock a garage, or view your camera feeds. The stakes aren't just privacy; they're physical security.
What changed this year? Two things. First, Matter 1.3 brought cross-platform device control, meaning your Apple Home hub can now talk to your Google Nest lock—but that also means a breach on one platform can ripple to others. Second, the rise of AI-powered home assistants has made voice-based access a bigger risk: a clever replay attack on your wake word can open doors. Auditing isn't a one-time project; it's the only way to maintain control.
Step-by-Step Guide: How to Audit Which Devices Have Access to Your Home
Here's the exact process I follow every quarter, and it takes about forty-five minutes if you're thorough. You'll need a laptop or a phone that can log into your router, plus a notepad (or a notes app) to track what you find.
Step 1: Survey Your Router's Device List
Start at the source. Open a browser and type your router's IP address—usually something like 192.168.1.1 or 10.0.0.1—or use the manufacturer's app. Log in with your admin credentials (if you haven't changed them from 'admin'/'password,' stop now and do that first). Look for a section labeled 'Connected Devices,' 'DHCP Client List,' or 'Device Manager.' You'll see every gadget that's on your network right now, each with an IP address, MAC address, and often a device name.
When I did this last, I found a 'TV_Samsung_Living_65' that I didn't own—turns out my son's gaming console was using a different naming convention. I also spotted an 'Unknown_Device_7C:5C:F8' that turned out to be a smart plug I'd installed for Christmas lights and forgotten about. Write down every device name and its MAC address. If you don't recognize something, flag it for investigation.
Step 2: Cross-Reference Your Smart Home Apps
Now open every app that controls a smart home device: your smart lock app, camera app, voice assistant app (Alexa, Google Home, Apple Home, SmartThings), and any automation platform (like Home Assistant or Hubitat). In each app, look for 'Linked Accounts,' 'Device Access,' or 'Permissions.' For example, in the Alexa app, go to Settings > Your Accounts > Linked Accounts to see which services can control your devices. In Google Home, it's under Settings > Works with Google. Remove any integrations you don't use—I had an old Philips Hue account I hadn't touched in two years that still had full access to my lights.
Step 3: Review Smart Lock and Camera Permissions
This is the critical one. For smart locks, open the lock's app (August, Yale, Schlage, etc.) and check the 'Users' or 'Access' section. You'll see a list of everyone who has a digital key—friends, family, former house sitters, dog walkers. Revoke any that aren't current. I once found a 'Guest Access' code I'd given to a neighbor to feed my cat back in 2022 that still worked. For cameras, check who has sharing permissions: in the Ring app, it's under Shared Users; in Arlo, it's under Profile > Sharing. Remove anyone who doesn't need live access to your driveway or nursery.
Step 4: Check Voice Assistant Skills and Routines
Voice assistants are the backdoor you forget about. In the Alexa app, go to Skills & Games > Your Skills and scroll through the list. Disable any skill you don't actively use—I had a 'Sleep Sounds' skill that I'd installed once and never used, but it had permission to access my name and zip code. In Google Home, go to Settings > Services > Explore > Your Actions and review the list. Also check your Routines: a routine that says 'Alexa, I'm home' can unlock your door—make sure only trusted commands are enabled.
Step 5: Audit Guest Networks and IoT Segmentation
Most modern routers let you set up a guest network that isolates visitor devices from your main smart home gadgets. If you haven't done this, now's the time. During your audit, check whether your guest network is active and who's connected to it. I had a guest network that was still using the default password from three years ago—anyone within range could have jumped on. Change the password, and consider enabling 'Client Isolation' so guest devices can't talk to each other.
Step 6: Document and Clean Up
Final step: create a simple spreadsheet or note with every device, its last seen date, and a status (Active, Unknown, Revoked). For unknown devices, block them in your router settings and change your Wi-Fi password if you suspect a persistent intruder. For old devices you no longer use, remove them from your account entirely—don't just disconnect them. Factory resetting a smart plug or camera you're discarding is the only way to ensure your credentials aren't stored on it.
What to Look For During Your Device Audit (Red Flags and Risky Permissions)
As you go through the steps above, here are the specific red flags I've learned to watch for. These are the things that turned a routine check into a security fix in my own home.
Unknown devices with generic names. If you see a device called 'ESP_XXXX' or 'Sonoff_01' and you don't own a cheap Wi-Fi relay or a temperature sensor, that's suspicious. ESP32/ESP8266 microcontrollers are common in DIY smart home projects, but they're also used in cheap, poorly-secured gadgets that can be compromised. I once found an 'ESP_7A3B' that turned out to be a smart plug from a no-name brand I'd bought on clearance and forgotten about—it had unpatched firmware from 2021.
Devices with outdated firmware. Many smart home devices don't update automatically. Check the firmware version on your cameras, locks, and hubs. If it's more than a year old, there's a good chance a known vulnerability exists. For example, some older Wyze cameras had a flaw that allowed remote access without authentication—fixed in a 2023 update, but only if you applied it.
Over-permissioned apps and skills. A skill that asks for access to your 'Full Name, Email, and Address' just to tell you a weather forecast is a red flag. The same goes for apps that request 'Microphone Access' when they only need to display a camera feed. I review app permissions on my phone every quarter—on iOS, it's under Settings > Privacy & Security; on Android, it's under App Permissions. Remove any that seem excessive.
Linked accounts you don't recognize. This is the one that catches most people. In your smart home app, check which third-party services are linked. I found that my Google Home was still connected to an old IFTTT account I'd used to turn on lights when my phone arrived home—I hadn't used IFTTT in years, but the integration was still active, giving a third-party service access to my location data.
Guest codes that never expire. If your smart lock allows temporary codes, check whether any are set to 'Never Expire.' I had a guest code for a contractor who worked on my house in 2024—it was still active when I audited in early 2026. Delete any code you didn't set to expire within a specific window.
How Often Should You Audit? Building a Routine That Sticks
I get asked this a lot, and my answer is based on what I've found works without becoming a chore. A full audit like the one above takes about 45 minutes, and I do it quarterly—January, April, July, October. That catches seasonal devices (Christmas lights, summer outdoor cameras) and follows the typical firmware update cycle. For the quick check, I do a 10-minute scan every month: log into my router, glance at the device list, and make sure nothing new or unknown has appeared. I also check my smart lock's access list monthly, because that's the highest-risk category.
Set a recurring calendar reminder. I have one on my phone that says 'Smart Home Audit' with a link to my checklist. The key is to make it a habit, not a crisis response. If you travel frequently or have new people staying over, do an extra audit after they leave—revoke their access immediately.
Beyond the Audit: Strengthening Your Home's Digital Perimeter
Once you've cleaned up your device list, you can take a few extra steps to make future audits easier and your home more secure. These are the things I've added after learning the hard way.
Enable two-factor authentication (2FA) on every smart home account that supports it. Your smart lock app, camera app, and voice assistant account should all require a second factor to log in. This prevents someone from taking over your account even if they steal your password. Most platforms (August, Ring, Google, Amazon) support 2FA now—turn it on in account settings.
Set up a dedicated IoT network. If your router supports VLANs (virtual LANs) or a separate IoT network, use it. This isolates your smart home devices from your main network where your laptop and phone live. Even if a cheap smart plug gets compromised, the attacker can't pivot to your computer. I use a TP-Link Deco XE75 that lets me create an IoT network with a single toggle in the app—took five minutes to set up.
Keep firmware updated automatically. Many modern smart home devices have an 'Auto-Update' option in their settings. Turn it on. For devices that don't, set a reminder to check for updates every quarter during your audit. I also subscribe to security mailing lists for my major devices (Ring, August, Google) so I get notified of vulnerabilities.
Use a password manager. I can't stress this enough. If you're using the same password for your smart lock app and your email, you're one data breach away from someone unlocking your front door. A password manager generates unique, strong passwords for each account and stores them securely. I use Bitwarden, but any reputable one works.
Auditing your home's device access isn't about paranoia—it's about practical control. Every time I run through this process, I find at least one thing I missed: an old account, a forgotten permission, a device that shouldn't be there. And every time I clean it up, I sleep a little better knowing that my front door, cameras, and microphones are only listening to the people I trust. Worth bookmarking this guide before your next quarterly audit.
Practical takeaway: Start with your router's device list and your smart lock's access list—those two checks will catch 80% of risks. Set a recurring monthly reminder for a 10-minute scan, and a quarterly 45-minute deep dive. Your home's digital perimeter is only as strong as your last audit.