Home » Home Security Phone Replacement Checklist 2026: Apps, Alerts, Access, and Recovery

Home Security Phone Replacement Checklist 2026: Apps, Alerts, Access, and Recovery

A new phone is not ready for home security when the app merely opens. Transfer ownership, multi-factor authentication, notifications, local-network permissions, camera access, lock credentials, monitoring contacts, and recovery before wiping the old device. Then trigger a real test event and run one-failure-at-a-time checks.

Phone replacement checklist at a glance

Area Pass condition Common failure
Account The correct owner signs in with current recovery and MFA A shared login or old phone holds the only second factor
Alerts Priority alarm, camera, lock, and offline alerts arrive promptly Focus mode, notification summary, or battery settings delay them
Local access Bluetooth, local network, location, and nearby-device functions work only as needed Remote control works but local setup or lock access fails
Security roles Owner, resident, guest, installer, and monitoring roles are correct The new phone is added as a broad administrator by default
Recovery A second trusted path works without the old phone The old device or SIM is the only recovery route
Retirement The old phone is removed from every account before reset or disposal It remains a trusted device with camera or door access

1. Keep the old phone until acceptance is complete

If the old phone is safe and available, keep it charged, connected, and locked while transferring. Do not erase it on the first day. Use it to verify account ownership, approve sign-ins, compare notifications, export records, and recover a missed credential. If the phone is lost or stolen, skip to the emergency section and revoke it instead of waiting.

2. Inventory every security-related app and role

List the alarm app, camera apps, smart locks, video doorbells, Apple Home, Google Home, Alexa, router, mesh Wi-Fi, cellular backup portal, monitoring portal, password manager, authenticator, email, carrier account, and any installer or landlord app. Record owner, administrators, members, recovery email, recovery phone, MFA method, device name, and service renewal.

3. Secure the new phone before adding home access

Install current operating-system updates, set a strong device passcode, enable biometric unlock where appropriate, enable device-finding and remote erase, protect the mobile-carrier account, install the password manager and authenticator from trusted sources, and confirm encrypted backup. Avoid restoring unknown configuration profiles or security apps from unofficial stores.

4. Transfer MFA and recovery first

Move authenticator accounts using the provider’s approved transfer process, verify backup codes, update trusted numbers, and test recovery from a second device or browser. Do not disable MFA simply to make migration easier. Keep alarm, camera, lock, email, Apple, Google, Amazon, and carrier recovery independent enough that one lost phone does not lock out every system.

5. Sign in as the correct person

Use named accounts rather than one household login. Confirm whether the user is owner, administrator, resident, guest, caregiver, installer, or monitoring contact. Give the minimum permissions needed. The new phone should not silently inherit camera recording, door unlock, alarm disarm, member-management, or billing privileges that the person does not require.

6. Review phone permissions one by one

Permission Why it may be needed Test
Notifications Alarm, entry, camera, lock, fault, and offline alerts Trigger each priority event and open it from the lock screen
Local network / nearby devices Discovery, setup, local control, bridges, locks Control one supported local device while on home Wi-Fi
Bluetooth Setup, nearby locks, sensors, commissioning Test only the device that requires it
Location Geofencing, arrival/departure, presence routines Test entry and exit without changing alarm safety unexpectedly
Camera / microphone QR setup, two-way talk, support diagnostics Allow only when the feature is used
Background activity Timely alerts, geofencing, device state Lock the phone and repeat a real event

7. Test priority notifications

Put any monitored alarm into approved test mode. Trigger a priority door, alarm state change, camera event, lock event, offline event, and low-battery or fault event where safe. Record event time, notification time, sound, vibration, watch delivery, focus mode, summary behavior, recipient, deep link, and event history. Use the HomeKit notification audit for Apple Home paths.

8. Test arm, disarm, panic, and duress safely

Verify the app’s armed states, entry and exit delays, local keypad fallback, test mode, and monitoring contact flow. Do not trigger panic, duress, police, fire, or medical functions without following the provider’s test instructions. Confirm the household can still control the alarm if the new phone is unavailable.

9. Verify cameras and evidence

Open live view on Wi-Fi and cellular data, trigger a recording, confirm timestamp and notification, use two-way talk if needed, check storage and retention, and export a test clip. Verify camera permissions and privacy modes. Remove duplicate alerts if both the manufacturer app and a smart-home platform notify the same low-value event.

10. Verify locks, codes, and phone credentials

Test the mechanical key, inside release, keypad, named code, phone key, watch key, Home Key, fingerprint, and remote control only where supported. Confirm a removed or expired credential fails. If the phone itself is a lock credential, verify the old phone no longer opens the door after retirement. Review any unlock-to-disarm automation separately.

11. Rebuild geofencing carefully

Confirm which household phones participate in presence, the correct property boundary, location permission, background activity, low-power behavior, and what happens when one person stays home. Test arrival and departure without allowing a convenience routine to disarm unexpectedly or leave the home unarmed. Keep a manual keypad or app fallback.

12. Check monitoring and emergency contacts

Update the phone number only if it actually changed. Verify monitoring contacts, call order, SMS permissions, verbal password, duress procedure, address, gate details, permits, and the provider’s test number. A new handset does not automatically update the monitoring center or household emergency plan.

13. Run one-failure-at-a-time tests

Failure Safe test Record
New phone offline Use airplane mode while another path remains Local alarm, second recipient, monitoring, recovery
Home internet down Disconnect WAN while keeping local power Local control, cellular backup, alerts, cameras, restoration
Primary account locked Verify recovery without changing ownership Email, MFA, backup code, trusted device, support
Old phone revoked Remove it from trusted devices Sign-in, camera, door, wallet credential, and notification access fail
AC power loss Use a safe planned outage Hub, router, communicator, camera, lock, and siren runtime

14. Handle a lost or stolen phone immediately

  1. Use the platform’s device-finding service to lock or erase the phone when appropriate.
  2. Contact the mobile carrier and protect the number against SIM takeover.
  3. Change the device-unlock risk, primary email, password-manager, and security-account credentials as needed.
  4. Revoke the phone from alarm, camera, lock, smart-home, router, and trusted-device lists.
  5. Remove mobile wallet keys, Home Key or similar credentials, and location-sharing access.
  6. Review event history for unexpected sign-ins, camera views, unlocks, disarms, or member changes.

If the phone may have exposed an address, alarm state, access code, or door credential, treat it as a property-security incident rather than only a handset loss.

15. Retire the old phone only after a final audit

Remove the old device from trusted devices, push-notification lists, home members where device-specific, lock credentials, mobile wallets, Bluetooth keys, authenticator approvals, password-manager sessions, carrier access, and device-finding. Verify access fails, then use the maker’s secure erase and recycling or trade-in process. Follow the security-device disposal checklist.

Document the migration

Record old and new device names, operating system, migration date, account owner, MFA and recovery changes, permissions, priority tests, revoked credentials, monitoring updates, and remaining issues. Store the result with the home-security documentation checklist.

Where Abode fits

For Abode, verify the named app user, arm/disarm permissions, notifications, CUE or location automations, cameras, locks, cellular backup, monitoring contacts, and outage behavior on the new phone. Compare the Abode Smart Security Kit, Abode Cam 2, and current Abode plans.

FAQ

Can I erase the old phone as soon as the security app works?

No. First test MFA, recovery, notifications, cameras, locks, alarm states, monitoring contacts, failures, and old-device revocation.

Do security alerts transfer automatically to a new phone?

Not reliably. App permissions, operating-system settings, focus modes, background activity, account roles, and device registration can all change.

What should I do if a phone with security access is stolen?

Lock or erase it, protect the carrier account, revoke trusted-device and door credentials, secure key accounts, and review alarm, camera, and lock history.

Should every household member be an administrator?

No. Use named accounts with the minimum alarm, camera, lock, member, and billing permissions each person needs.

Fill the Apple Home gap before retiring the old phone

A normal phone migration can appear complete while Apple Home security still has hidden failures. The Home app may open, yet a shared resident is missing, a camera only works on the home Wi-Fi, an Apple Watch no longer receives the useful alert, or an old phone remains trusted. Treat the new phone as a new security console and accept it only after every control, alert, recording, and recovery path has been tested.

Record the Home before changing devices

On the old phone, capture the Home name, room names, accessory names, resident list, hubs, bridges, automations, cameras, recording settings, and notification rules. Do not place setup codes or recovery codes in ordinary screenshots. Put HomeKit labels, QR codes, serial numbers, and bridge details into the HomeKit setup-code inventory, stored separately from the phone.

Item Old-phone evidence New-phone pass
Home and rooms Names and accessory count No duplicate Home, missing room, or generic accessory
People Owner and invited residents Correct people retain the intended role
Hubs and bridges Connected or standby state Remote access survives away from Wi-Fi
Cameras Live, recording, and notification choices Live view, event history, audio, and alerts match
Automations Trigger, conditions, and action One safe test proves the actual result
Recovery Trusted contacts and separate code storage Owner can recover without the old handset

Confirm that the Home is using a stable hub path

The new iPhone is not the home hub. Remote control, camera recording behavior, and automations can depend on a compatible Apple home hub and the home’s network. Check which hub is connected, which is on standby, and whether each is in the expected Home. Use the home-hub redundancy guide to test one hub outage before blaming the new phone.

Run one test on home Wi-Fi and repeat it on cellular data. A live camera that works only while the phone is on the same network has not passed remote access. Record the time of each test and the hub state shown before and after.

Transfer ownership and invitations without creating a second Home

Sign in with the intended Apple Account before opening invitations or adding accessories. If the Home appears empty, stop. Do not create a replacement Home or reset bridges until the owner, account, and sync state have been checked. A duplicate Home can split rooms, people, accessories, and automations across two records.

Compare the people list on both phones. Each person should have the minimum role required. Remove a temporary test member and verify the removed account loses access by following the HomeKit member-removal test. Do not use a shared Apple Account as a substitute for invitations.

Recheck every security notification

Notification permission at the phone level is only the first layer. Check Home notifications, camera or accessory event choices, time and presence conditions, Focus behavior, sound, vibration, and Apple Watch routing. Generate controlled events instead of assuming settings transferred.

  1. Trigger one door or window sensor and record delivery time.
  2. Trigger one camera event in daylight and low light.
  3. Lock the new phone and repeat the event.
  4. Enable the normal Focus mode and repeat it again.
  5. Move away from home Wi-Fi and repeat over cellular data.
  6. If Apple Watch is used, run the Apple Watch security-alert test with the phone locked and unlocked.

Pass only when the alert identifies the correct accessory and room, reaches the intended person, opens the right view, and arrives within the household’s written response limit.

Audit trusted devices and sessions

A phone replacement can leave the old device signed in to Apple, the alarm app, the camera app, password managers, email, monitoring portals, and mobile carrier tools. List every system that can arm, disarm, unlock, view video, export evidence, change residents, or reset a password. Use the trusted-device and session audit to remove the old handset deliberately after the new one passes.

If the old phone was lost, stolen, traded in early, or controlled by someone else, treat the change as an account-security event. Revoke sessions, change exposed credentials, review recent activity, check forwarding and recovery details, and document the time of each action.

Keep emergency access independent of one phone

The replacement process must not leave the owner unable to enter, disarm, or call for help when the new phone is unavailable. Test a physical key, keypad code, key fob, trusted resident, and monitoring contact where applicable. The HomeKit emergency-access checklist separates ordinary app convenience from the backup route needed during battery, network, account, or phone failure.

Run a 60-minute HomeKit phone-replacement acceptance test

  1. Minutes 0–10: Compare the Home, people, rooms, hubs, bridges, accessories, and automations on both phones.
  2. Minutes 10–20: Test one sensor, one lock or controller, one camera live view, one event recording, and one safe automation.
  3. Minutes 20–30: Test notifications with the phone unlocked, locked, and in the resident’s normal Focus mode.
  4. Minutes 30–40: Leave home Wi-Fi. Test remote status, live video, an allowed control, and one alert over cellular data.
  5. Minutes 40–50: Turn off one non-primary hub or disconnect one bridge safely. Record what continues, what stops, and how recovery is confirmed.
  6. Minutes 50–60: Remove one test member, revoke one test session, use one backup entry method, and confirm the owner can recover without the old phone.

Do not erase, trade, or factory-reset the old phone until all six stages pass and another responsible person can follow the recovery record. If any test fails, preserve the old phone, note the exact state, and change one variable at a time.

Close the migration with evidence

Write the new phone model, operating-system version, Apple Account owner, security-app versions, hub state, test date, failed steps, fixes, removed sessions, and old-phone disposal method. Store the record with the household security documentation, not only on the replacement phone. Repeat the alert and remote-access tests after a major iOS, router, hub, bridge, or security-app change.

Have your say!

0 0