---
title: "WP Cerber Global Settings to Restrict Website Access"
description: "In this article: WP Cerber Global Settings A WordPress plugin that restricts visitors to an “under construction” or login page can be helpful depending on the type of website. However, that..."
url: https://www.inmotionhosting.com/support/edu/wordpress/wp-cerber-restrict-website-access/
date: 2019-11-04
modified: 2021-08-16
author: "InMotion Hosting Contributor"
categories: ["Website", "WordPress Tutorials"]
type: post
lang: en
---

# WP Cerber Global Settings to Restrict Website Access

**In this article:**

- [WP Cerber Global Settings](#settings)

A WordPress plugin that [restricts visitors to an “under construction” or login page](/support/edu/wordpress/how-to-create-an-under-construction-page-using-wordpress/) can be helpful depending on the type of website. However, that plugin likely isn't security-focused. And it serves no purpose until you need that maintenance page. That's not the case with the [WP Cerber Security](/support/email/wp-cerber-security-antispam-bot-detection-settings/) plugin.

Instead, WP Cerber Security includes this restrictive feature within a list of many others. Therefore, you have a plugin that accomplishes more than one goal.

Furthermore, WP Cerber fights brute force attacks during maintenance time by using your [white IP access list](/support/edu/wordpress/how-to-modify-wp-cerber-security-access-lists/) and other methods to restrict who can register, login, or access the login page.

Below we'll cover how to **restrict WordPress access to authorized users**.

## Edit WP Cerber Global Settings

1. [Log into WordPress](/support/edu/wordpress/logging-into-wordpress-dashboard/).
2. Hover over **WP Cerber** on the left and click **User Policies**.
3. Click the **Global** tab.
4. Toggle **Authorized users only** to show green. The remaining options are optional but improve your security and users' experience.
5. (Optional) Toggle [Use White IP Access List](/support/edu/wordpress/how-to-modify-wp-cerber-security-access-lists/) to allow all visitors access from whitelisted IPs.
6. Edit the **User Message** which shows above the login section.
7. (Optional) Fill in **Redirect to URL** for all URL requests except the login page - *wp-admin*. Popular examples include a maintenance, registration, or custom login page.
8. (Optional) **Restrict email addresses** to explicitly “**deny all**” or “**permit only**” a specified list of users in the text box below. Use this if you only want same domain accounts registered to the website as brute force protection.
9. Add **Prohibited usernames** for brute force protection against malicious activity - *e.g. “admin”, “administrator”, “root”, and your name*.
10. **User session expiration time** determines how long an user can stay logged in at once.
11. **Sort users in the dashboard** by date/time of website registration.
12. Click **Save Changes**.

![WP Cerber Global User Policies](https://www.inmotionhosting.com/support/wp-content/uploads/2019/08/wp-cerber-global-settings-1024x938.png)*Toggle the **Authorized users only** slider to show green*

Ask about our Nginx-powered [WordPress Hosting](https://www.inmotionhosting.com/wordpress-hosting) for faster performance to match your enhanced website security.
