# Set up sign-in protection on Login & Access

Set BetterShield’s login attempt limits, hidden bot check, public form limits, allow and block lists, trusted proxies and session limits.

Login & Access controls who may try to sign in, how often, and how long sessions last. It is on **BetterShield › Protect › Login & Access**. Edits wait in a bar with **Save** and **Discard**.

## How this site sees you, and lockouts

**How this site sees you** reads your own request (nothing is stored) and says whether visitors can be told apart.

- If lockouts are not running, it says why. Usually the fix is naming your proxy under **Trusted proxies**.
- If your request came through Cloudflare unannounced, press **Yes, this site is behind Cloudflare**. **Turn that off** withdraws that trust.

**Lockouts** lists recent pauses from sign-in and the public forms, running ones first, by network (such as 203.0.113.0/24). **Release now** ends a running one.

> **Note:** Only a verified address is ever locked out. Others are recorded, never locked.

## Sign-in protection

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Pause sign-in after repeated failures** | After **Failures allowed** (3 to 100) wrong passwords from one connection within **Counted within (minutes)**, sign-in from it pauses for **Pause lasts (minutes)** (both 1 to 1440). | Stops brute-force password guessing without locking the account. | On: 5 in 15 minutes, paused 15 minutes |
| **Refuse obviously automated submissions** | The hidden bot check: an invisible field and a clock on the sign-in, registration, comment and store account forms. Refuses scripts that fill every field or submit within two seconds. | Cuts bot noise; people see nothing. | On |
| **Slow down repeated failed sign-ins** | After two wrong passwords from one connection, the browser solves a small puzzle before the next try. Needs JavaScript, and HTTPS or localhost. | Guessing below the limit costs time; an unsolved puzzle never counts. | Off |
| **Tell an account holder about a sign-in from a new network** | Emails the account's own address the first time it signs in from a new network, at most once a day. Blocks nothing. | The person who knows is told. | Off |

A connection paused again within a day is paused twice as long each time, up to a day; releasing one resets the doubling. Wrong two-factor codes and wrong application passwords also count. If the attempts named a real account, its owner is emailed an unlock link (see [Locked out](/docs/locked-out/)).

On multisite, each site keeps its own counts, lockouts and lists.

## Signing in

Six sign-in fixes, all off by default, described in [Hardening](/docs/hardening/).

- **Change the sign-in address**: moves sign-in to an address you choose.
- **Refuse application passwords**: for site managers, or everyone.
- **Refuse passwords found in known breaches**: checks new passwords against Pwned Passwords.
- **Keep low-privilege accounts out of the dashboard**: sends a chosen role from wp-admin to the front page.
- **Hide the dashboard from visitors**: signed-out visitors get a 404 at /wp-admin/.
- **Strengthen and rotate the sign-in keys**: adds a secret to session keys.

## Request protection

Counted apart from sign-ins, so a form never locks you out of your dashboard. Each form has **Allowed before it closes** (3 to 100), **Counted within (minutes)** and **Closed for (minutes)** (both 1 to 1440).

| Option | Past the limit | Default |
|---|---|---|
| **Hold a burst of comments for moderation** | Further comments from that connection wait in moderation. Nothing is discarded; moderators are never held. | On: 10 in 10 minutes, closed 30 minutes |
| **Slow repeated password reset requests** | Further requests get the answer a successful one gets, so no account is revealed. Accounts are never affected. | On: 8 in 15 minutes, closed 15 minutes |
| **Slow repeated sign-ups** | Further sign-ups are refused until later. Only where registration is open. | On: 8 in 1 hour, closed 1 hour |

Before you save, new numbers are replayed against the last two days of attempts.

## Allowed and refused

| List | What it does | Default |
|---|---|---|
| **Always allowed** | Addresses never locked out, held by form limits or given the puzzle. Addresses only. | Empty |
| **Never allowed to sign in** | Refuses sign-in, never browsing. Each entry names an address or range, a username, a user-agent fragment, or a mix, with an optional note. | Empty |
| **Trusted proxies** | **One address or range per comma** for a reverse proxy in front of the site, so the visitor address it forwards (X-Forwarded-For) is believed. Cloudflare needs no entry. | Empty |

A **Never allowed to sign in** entry has these fields, plus an optional **Note**:

- **IP address or CIDR range**: matches verified connections only.
- **Or a username**: on its own, refused from anywhere, even an allowed address, with the answer a wrong password gets. Beside a range or user agent, refused only from there. Your own username cannot be added.
- **Or a user-agent fragment**: four characters or more. On its own, it applies to every connection.

Ranges can be no wider than /8 (IPv4) or /32 (IPv6). Each list holds up to 500 entries.

## Sessions

| Option | What it does | Default |
|---|---|---|
| **Sign out after idle (minutes)** | Signs a session out after this long without activity, yours included. | 0 (no timeout) |
| **Sessions per account** | When an account signs in past the cap, its oldest session signs out. | 0 (no cap) |

> **Note:** The idle timeout is 0 (off) or 5 to 1440 minutes (one day). The session cap (0 to 100) is unavailable where another plugin replaced WordPress's session storage.

**Who is signed in** lists each session's start, last activity and network. **Sign out all their sessions** signs one account out everywhere. **Sign out everyone you can** ends every session you may end, yours included. Both ask **Yes, do it** first.

## Good to know

- Minimum password lengths are under **Settings › General**. See [General settings](/docs/general-settings/).
- With **Ask for my password before an action that removes a protection** on, loosening a setting, releasing a lockout or signing people out asks for your password.
- Safe mode, from your recovery link, pauses everything on this screen.

## Related

- [Hardening](/docs/hardening/)
- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Your profile](/docs/your-profile/)
- [Locked out](/docs/locked-out/)
- [General settings](/docs/general-settings/)
- [Cloudflare](/docs/cloudflare/)
