Audit by impact, not by menu order

Working through Settings top to bottom produces a long session and little improvement, because the controls that matter most are scattered and the ones that matter least are numerous.

Order the work by consequence: account takeover first, then physical access, then broad app permissions, then accidental sharing. Everything else is refinement.

The account is the highest-consequence surface

An attacker with your Apple Account has your synchronised library, your backups, and often the ability to lock you out. No local setting compensates for that.

Review the devices signed in, confirm two-factor authentication is active, and check that recovery contacts and trusted phone numbers are ones you still control. Old recovery routes are a standard attack path.

Then physical access

Lock Screen previews, widgets, and Control Center access determine what someone holding the locked phone can read without unlocking it.

Message previews in particular leak verification codes and conversation content to anyone glancing at a table.

Then permissions and sharing

  • Review Photos access per app, preferring selected photos over full library access.
  • Check Camera, Microphone, Location, and Contacts for apps that no longer need them.
  • Review AirDrop receiving settings, which many people leave open.
  • Check Shared Album participation and any Shared Photo Library.
  • Review analytics and advertising settings, which are low-risk but easy wins.

Two ways audits go wrong

  • Turning off services without understanding what breaks, then re-enabling everything in frustration.
  • Tightening app permissions while ignoring account recovery, which is the higher-consequence control.

A fictional example

Noah starts with a non-sensitive test: “Review Apple Account devices, multifactor authentication, and recovery.” Next, Noah follows the second check: “Audit Photos, Camera, Microphone, Location, and Contacts permissions.” This fictional scenario demonstrates the decision process; it is not a report of product testing.

Common mistakes

  • Turning off random services without understanding breakage
  • Ignoring account recovery

What this workflow does not change

  • Turning off random services without understanding breakage
  • Ignoring account recovery

Questions people ask

Where are privacy settings now?

Current menu names vary by release; start with Privacy & Security and app-specific settings.

Sources and further reading