Security modes

One choice sets four switches. What None, Normal and Strict each turn on, and when to leave them alone and use Custom.

  • Beginner
  • 4 min read
  • Applies to 2.0

Where it lives

User Access → Security, at the top of the tab: four cards, then the switches the cards set.

The Security tab: the four mode cards above the two-factor, reCAPTCHA, IP and logging switches.

What each mode turns on

Picking a card and saving writes all four switches at once.

ModeIP blockingAudit logTwo-factorreCAPTCHA
Noneoffoffoffoff
Normalononoffoff
Strictonononon
Customleft exactly as you set them

Normal is the sensible default: the site records what happens and honours your IP lists, without asking members for a second factor.

Strict turns on two things that need setting up before they help anyone. Two-factor authentication will start emailing codes, and reCAPTCHA does nothing at all until you have entered a site key and a secret key — see reCAPTCHA. Choose Strict once those are ready, not before.

When the mode leaves your switches alone

Two cases, both deliberate:

  • You saved without changing the card. The mode you already had is applied once, when you pick it. Saving again with the same card in place does not re-apply it — otherwise a switch you had just turned off by hand would come straight back.
  • The card is Custom. Custom never applies a preset. That is the whole point of it.

So the usual way to work is: pick the mode nearest what you want, save, then switch to Custom and adjust individual switches from there.

Turning reCAPTCHA off with a mode does not lose your site and secret keys. They stay where you typed them, ready for when you turn it back on.

What the mode does not do

The card is not a wall. It sets switches, and it is the switches that act. Nothing about a mode throttles logins harder, and no mode closes your site to the public — the strictest setting still lets a visitor reach the door and be turned away only if their address is on the blocked list.

Two other parts of the plugin read the mode directly rather than through a switch: the password policy applies only when the mode is not None, and one section of the Emails tab is hidden in None. If you have set a password policy and it seems to be ignored, check that the mode is not None.

Coming from version 1.x? The modes used to describe what they would do without doing any of it — choosing Strict changed nothing at all. Since 2.0 they apply. If you had picked a mode on an older site and set the switches by hand underneath it, look at the Security tab once after updating: the first time you save with a different card selected, the preset takes effect.

Something missing or out of date? Tell support.