Jeyki SecurityCybersecurity consulting
Facebook

Lock Down Facebook and Instagram for Parents and Seniors: A Step-by-Step Meta Guide

A calm, step-by-step Meta Accounts Center lockdown for parents, seniors, and the family members helping them: passwords, MFA, recovery details, sessions, WhatsApp devices, and scam rules.

← Back to guidesPublished 2026-08-11 · Updated 2026-08-11

Who this guide is for

This is the practical lockdown walkthrough for households where Facebook, Instagram, Messenger, or WhatsApp are part of daily life, especially for parents and seniors. You can do it for yourself, or sit with a family member and do it together. The goal is not to make anyone tech-phobic. The goal is fewer account takeovers, fewer scam messages sent in their name, and a recovery path that still belongs to them if something goes wrong.

Before you touch settings: gather the right pieces

Most failed lockdowns happen because the recovery email is weak, the password gets written on a sticky note, or nobody knows which phone number still works. Take five minutes to prepare.

  • Confirm they can open the email address used for Facebook or Instagram recovery
  • Make sure that email itself has a strong unique password and MFA if possible
  • Choose a password manager or another safe way to store a long unique Meta password
  • Have their working mobile number available, but do not rely on SMS as the only defense
  • Agree that you will not reuse an old password from banking, email, or shopping sites
  • If this is a shared household help session, write down what you changed so future you is not guessing

Step 1: Open Meta Accounts Center and review what is linked

On Facebook or Instagram, open settings and find Accounts Center. Review which accounts are linked: Facebook, Instagram, and any related profiles. This is also where shared security settings often live. If more accounts are linked than the person actually uses, note that before changing passwords so you understand the blast radius.

  • List every linked account you can see
  • Note the primary contact email and phone number currently on file
  • Check whether a business Page or professional account is attached to a personal login

Step 2: Set one strong unique password

Change the Meta password to a long unique one and store it properly. If the person struggles with password managers, set the manager up with them and practice unlocking it once. A password written in a notebook kept at home is still better than 'Sunshine2020!' reused everywhere, but a password manager is the better default when the household can handle it.

  • Use a unique password only for Meta
  • Do not email the new password to other family members as a backup plan
  • If multiple relatives help with the account, decide who is the trusted helper and avoid password sprawl

Step 3: Turn on stronger two-factor authentication

Enable MFA in Accounts Center. Prefer an authenticator app over SMS when the person can manage it. If SMS is the only realistic option for a senior, still enable it rather than leaving MFA off, then reduce other risks harder: unique password, clean recovery email, and no code-sharing.

  • Remove old phones or methods that no longer belong to them
  • Save backup codes in a safe place the right family member can find during an emergency
  • Explain clearly: nobody legitimate needs the MFA code, including 'Facebook support' in chat

Step 4: Clean recovery email, phone number, and sessions

Attackers love stale recovery methods. Confirm the email and phone number are correct, remove old ones, and sign out of sessions or devices that look unfamiliar or unused. If there is a session in another country or on a device nobody recognizes, treat that as urgent.

  • Recovery email should be an inbox they still control
  • Remove former phone numbers and ancient alternate emails
  • Sign out unknown devices and review logged-in sessions
  • Revoke weird linked apps or old site connections with broad access

Step 5: Check WhatsApp and Messenger risk in the same sitting

Do not stop at Facebook. Open WhatsApp linked devices and remove anything unrecognized. Remind them that a code on the screen is not a customer-service step to read aloud to a stranger. On Messenger and Facebook chat, tighten who can message them if they get frequent stranger spam.

  • WhatsApp: Linked devices -> remove unknowns
  • Never share linking codes, QR codes, or 'to activate your computer' prompts
  • Be careful with friend requests and 'Hi grandma' messages from new accounts
  • If money, gift cards, or secrecy come up, stop and call the real relative on a known number

Step 6: Reduce scam surface without making the account miserable

Lockdown should still leave them able to enjoy family photos and groups. Focus on the settings that reduce impersonation and stranger pressure.

  • Review privacy defaults for who can see posts, friend lists, and personal details
  • Limit how easily strangers can friend or message them if that is a current problem
  • Turn off or reduce unnecessary public visibility of phone number, email, and birthdate
  • Warn about fake marketplace, shipping, romance, and 'your account will be disabled' lures
  • Create a household rule: no codes, no remote-access apps, no emergency money from inbound chat alone

Step 7: Leave a simple household recovery sheet

When the session ends, the person should have a one-page note: which email controls Meta, where the password is stored, where backup codes live, who the trusted helper is, and what to do if Facebook says the password is wrong tomorrow. That boring sheet prevents panic and prevents relatives from undoing the lockdown with weak shared passwords later.

If the account is already hacked

Stop the setup checklist and switch to recovery mode. Try to control the email account first, use official Meta hacked-account flows, document what changed, and warn friends not to trust money requests. After access returns, come back and complete every lockdown step above. If the senior is overwhelmed, it is better to get hands-on help than to keep guessing through recovery screens while the attacker still has a session.

Revisit the lockdown after any big life change

Security settings drift after moves, new phones, new email providers, or a change in who is the primary trusted helper. Treat those moments as a trigger to redo the review, not just the day it was first set up.

  • New phone: confirm MFA and authenticator app carried over correctly rather than silently falling back to SMS
  • New email address: update Meta's recovery email deliberately rather than leaving the old inbox as the fallback
  • Change in trusted helper: rotate the password and re-confirm who holds backup codes

Frequently asked questions

Should adult children just take over the Facebook password?

Only with clear consent and a plan. A trusted helper can be excellent. Quiet password-taking often creates confusion, locked-out relatives, and no durable recovery path. Better: set up a password manager, MFA backup codes, and one named helper.

Is SMS two-factor good enough for a senior?

It is much better than no MFA. Authenticator apps are stronger when usable. If SMS is the only method they will consistently use, enable it and harden everything around it: unique password, clean recovery email, and a hard rule never to read codes to callers or chat contacts.

Do they need Meta Verified for this lockdown?

No. The lockdown steps above matter more than a paid badge for ordinary personal accounts. Verification can help some public figures with impersonation, but it is not the foundation of household account safety.

What is the single most important step if we only do one thing today?

Make sure the recovery email is strong and under their control, then set a unique Meta password and MFA. That trio prevents a large share of ugly takeover outcomes.

How often should we redo this lockdown check?

Once a year at minimum, and immediately after a new phone, a new email address, or any suspicious activity. A short annual check is far less disruptive than a full recovery after an actual takeover.

What is the biggest risk if a senior keeps their Meta password written on paper?

The main risk is not the paper itself if it is kept somewhere private at home; it is treating that written password as permanent and never rotating it, or accidentally photographing and cloud-syncing the note. A password manager with one strong master password removes both risks.

Official resources