Android’s built in security has changed more in the last year than in the previous five combined. Android 17 added real time scam call blocking, theft protections that turn on by default, and an expanded Play Protect that watches for behavior, not just known malware signatures. Most of it is off by default or buried in a menu, so here is what to actually turn on, in order of how much it matters.
The quick answer: set a strong screen lock with biometrics, then turn on Advanced Protection Mode in Settings, Security and privacy (it requires Android 16 or newer and a screen lock already set). Confirm Google Play Protect is scanning apps in real time, turn on Theft Detection Lock and Remote Lock under Find Hub if your phone has Android 17, switch any account that supports it to a passkey instead of a password, and review the Permission manager for apps holding onto background location or microphone access they do not need. Those five actions cover the overwhelming majority of real world Android compromise.
Turn on Android’s built in theft protections
Android 17 made Theft Detection Lock and Remote Lock the default on new devices, and both are worth confirming on an upgraded phone too. Theft Detection Lock uses on device motion sensors to recognize the kind of sudden movement that follows a phone being snatched from someone’s hand, and locks the screen automatically. Remote Lock, part of the Find Hub (formerly Find My Device) system, now supports biometric authentication before a phone can be marked as lost, which closes a real gap: previously, someone who had watched you enter your PIN could disable tracking themselves. Check Settings, Google, All services, Find Hub and confirm both are enabled.
Turn on Advanced Protection Mode
Advanced Protection is Google’s single strongest security toggle, and it deliberately trades some convenience for it. Go to Settings, Security and privacy, Advanced Protection, and turn on Device Protection. It requires Android 16 or newer and a screen lock already configured. Once on, it disables sideloading apps outside the Play Store entirely, turns off device to device unlocking via trusted devices, and disables Chrome’s WebGPU feature, a modern source of browser exploits. On Samsung phones running One UI 8, the same feature lives under Settings, Google, All services rather than the stock Android path.
This is genuinely aimed at high risk users (journalists, activists, executives) as much as everyday people, so the sideloading restriction is worth weighing if you rely on an app not distributed through the Play Store.
Let Play Protect actually do its job
Google Play Protect scans every app on the phone, but its 2026 update expanded what it looks for well beyond matching known malware. It now flags apps abusing SMS forwarding permissions, apps that hide behind an accessibility overlay to intercept what you type, apps that conceal or change their own icon after installation, and apps running suspicious background processes. It also now scans APK files downloaded through Chrome before you even open the install prompt, and hides one time passwords from most apps for three hours after they arrive, closing a common OTP-theft trick used by malicious apps with notification access.
Confirm it is active under Settings, Security and privacy, Google Play Protect; it should show “No harmful apps found” and app scanning turned on.
Stop scam calls before they start
A new Android 17 feature lets participating banking apps verify an incoming call’s caller ID against known spoofing patterns; if the system detects a call impersonating a bank using faked caller ID, Android can terminate it automatically. Google has confirmed partner banks including Revolut, Itau Unibanco, and Nubank for this feature, with more expected to join. It works passively once your bank’s app supports it and requires no setup beyond having that app installed and updated.
Switch to passkeys where you can
A passkey replaces a password with a cryptographic key tied to your device and unlocked by your existing screen lock (fingerprint, face, or PIN). It cannot be phished, guessed, or reused across a data breach the way a password can, because there is no shared secret being typed anywhere. Google, most major banks, and a growing number of shopping and social apps now support them; check the security settings inside each account for a “passkey” or “sign in without a password” option.
Keep the phone and its apps current
Monthly security patches close specific, publicly documented vulnerabilities, and the gap between a patch shipping and attackers reverse-engineering what it fixed keeps shrinking. Check Settings, Security and privacy, System and updates for a pending patch, and separately confirm Play Store apps are set to auto-update rather than sitting on an old version with a known, already-patched flaw. Delaying an update for a few days to see if others report problems is reasonable; delaying it for months is not.
Turn on the Find My Device network
Beyond Remote Lock and Theft Detection Lock covered above, Android’s Find Hub also runs a crowd-sourced offline finding network, similar in concept to Apple’s Find My network: nearby Android phones can anonymously help locate a lost device even when it has no signal of its own, using encrypted, privacy-preserving location reports. Confirm it is turned on under Settings, Google, All services, Find Hub, Find offline devices, since it is a genuinely different capability from the phone simply reporting its own location, and it matters most in exactly the situation where a stolen phone is deliberately switched off or has no data connection.
Audit app permissions regularly
Go to Settings, Privacy, Permission manager and sort by permission type rather than by app. Background location and microphone access are the two worth checking most often: an app that only needs your location while it is open in the foreground should never be set to “Allow all the time.” Revoke anything you cannot immediately explain a reason for.
Priority settings at a glance
| Setting | Where to find it | Why it matters |
|---|---|---|
| Screen lock with biometrics | Settings, Security and privacy, Screen lock | Everything else on this list depends on this being set first |
| Advanced Protection Mode | Settings, Security and privacy, Advanced Protection | Blocks sideloading, disables risky Chrome features, hardens the whole device |
| Theft Detection Lock / Remote Lock | Settings, Google, Find Hub | Automatic lock on snatch-and-run theft, biometric gate on remote actions |
| Google Play Protect | Settings, Security and privacy, Play Protect | Behavioral scanning, not just known-malware matching |
| Permission manager | Settings, Privacy, Permission manager | Removes standing access apps no longer need |
What not to rely on
- SMS based two factor authentication alone. It is far better than nothing, but SIM swap attacks specifically target it; a passkey or an authenticator app is stronger.
- Third party “security” or “cleaner” apps promising malware scanning. Several of the worst offenders for excessive permissions and ad fraud on the Play Store have historically been apps marketed as phone cleaners or boosters. Play Protect, already running in the background, covers what a legitimate device needs.
- Assuming a factory reset alone removes all risk after a compromise. It removes malicious apps, but if the Google account itself was compromised (not just the device), a reset does not fix that; change the account password and review linked devices in the account’s own security settings too.
Frequently asked questions
Is Advanced Protection Mode overkill for an average user?
It depends entirely on whether the sideloading restriction affects an app you actually need. For most people who only install from the Play Store anyway, there is no practical downside and a real security upside.
Can I turn Advanced Protection back off if it is too restrictive?
Yes, it can be disabled from the same settings screen at any time, though Google intentionally adds a short waiting period before it fully turns off, similar to how account recovery works.
Do I need a separate antivirus app on Android?
For the overwhelming majority of users, no. Google Play Protect scans continuously and system-level, and a third party scanner app cannot see anything more than what Play Protect and the Permission manager already expose.
What is the single most effective thing on this list?
A proper screen lock with biometrics enabled first, since Advanced Protection Mode and several other protections depend on one already being set.

A tech Journalist and Photographer, Dhawal Sharma is a technology enthusiast who loves to research the latest innovations and technology. He has contributed to the Honor Community for a very long period and has crucial expertise in writing tech news and reviewing smartphones and laptops. Analyzing and bringing the facts about any piece of tech is what he loves the most. He is a great product photographer and is the Gizmopedia of TheLeaker. Find him on Facebook and Instagram, and you can also email him at [email protected].
