Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Terminal Servers
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Configuring Policies
    2. Consents
    3. PII Protection
    4. Time-Based Policy
    5. Malvertising Protection
    6. Login Guard
  • Secure Access (ZTNA)
    1. Introduction to ZTNA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Login Guard

In this document
  • Overview
  • How it works
  • Configuration
  • Example Scenarios
    • Allow only company email domains
    • Deny company email domains
  • Summary

Overview

Login Guard helps organizations control which email domains users can use when signing in to websites.

When this feature is enabled, DefensX evaluates the email domain used during a website sign-in flow and applies the selected policy action. This allows organizations to either require users to sign in with approved company email domains or prevent the use of company email addresses on selected websites.

Screenshot%202026 07 08%20at%2013.45.42%20copy

Email Domains page is used to define the approved company domains for Login Guard. These domains are then used by credential filter policies to allow or block sign-in attempts based on the configured Login Guard action.

Screenshot%202026 07 08%20at%2013.42.45
Tip
Login Guard is available as a CORE+ feature.

How it works

Login Guard has three available actions:

No Act (Disabled): Applies no restriction.

Allow only company email domains: Allows users to sign in only with the email domains configured under Email Domains. All other email domains are blocked.

Deny company email domains: Blocks users from signing in with the email domains configured under Email Domains. Other email domains are allowed.

Screenshot%202026 07 08%20at%2014.07.37

Configuration

First, configure your company email domains.

Navigate to Policies → Email Domains.

Enter one or more company-owned domains in the Domains field, separating them with commas, semicolons, or line breaks; duplicate entries are ignored. Then click Save.

Screenshot%202026 07 08%20at%2013.44.03
Note
At least one company email domain must be configured before Login Guard can be used. If Login Guard is enabled without a configured domain, DefensX displays an Email Domains Required message and prompts the admin to configure the email domains.
Screenshot%202026 07 08%20at%2013.46.19

Next, enable Login Guard in the relevant policy.

To do this, go to Policies → Policy Groups and click the Configure button on the relevant policy group.

Screenshot%202026 07 08%20at%2013.48.00%20copy%202

Under Credential Filters, configure Login Guard by selecting the action that matches your needs: No Act, Allow only company email domains, or Deny company email domains.

Screenshot%202026 07 08%20at%2013.45.42
Important
Make sure the Custom URL Group or category is allowed by the policy first. Login Guard then controls which email domains can be used during sign-in.

Example Scenarios

Allow only company email domains

Scenario 1: Require Company Email Domains for ChatGPT Sign-In

This configuration allows users to sign in to ChatGPT only with approved company email domains. Login Guard blocks sign-in attempts that use a personal or unapproved email domain.

To configure this:

Create a Custom URL Group for ChatGPT.

Screenshot%202026 07 08%20at%2015.06.04

Add the relevant ChatGPT domains to the Custom URL Group.

Screenshot%202026 07 08%20at%2015.07.00

Then, create a new policy for Login Guard and select Credentials as the policy type.

Screenshot%202026 07 18%20at%2000.17.54

In the relevant policy, set the Custom URL Group action to Allow.

Screenshot%202026 07 18%20at%2000.21.48

Set Login Guard to Allow only company email domains.

Screenshot%202026 07 08%20at%2015.13.37%20copy

Blocked Sign-In Message:

Screenshot%202026 07 14%20094726

Scenario 2: Require Company Email Domains for AI Website Sign-In

This configuration allows users to sign in to AI websites only with approved company email domains. Login Guard blocks sign-in attempts that use a personal or unapproved email domain.

To configure this:

Create a new policy for Login Guard and select Credentials as the policy type.

Screenshot%202026 07 18%20at%2000.18.41

Set the Artificial Intelligence category action to Allow.

Screenshot%202026 07 08%20at%2015.54.34

Set Login Guard to Allow only company email domains.

Screenshot%202026 07 08%20at%2015.13.37

Blocked Sign-In Message:

Screenshot%202026 07 14%20094726

Deny company email domains

Scenario 1: Prevent Sign-In to Reddit with Company Email Domains

This configuration prevents users from signing in to Reddit with company email domains. Login Guard blocks sign-in attempts that use a company email domain.

To configure this:

Create a Custom URL Group for Reddit.

Screenshot%202026 07 10%20at%2014.12.16

Add the relevant Reddit domain to the Custom URL Group.

Screenshot%202026 07 10%20at%2014.13.25

Then, create a new policy for Login Guard and select Credentials as the policy type.

Screenshot%202026 07 18%20at%2000.19.40

In the relevant policy, set the Custom URL Group action to Allow.

Screenshot%202026 07 18%20at%2000.22.56

Set Login Guard to Deny company email domains.

Screenshot%202026 07 10%20at%2014.16.01%20copy

Blocked Sign-In Message:

Screenshot%202026 07 14%20094949

Scenario 2: Prevent Sign-In to Social Media Websites with Company Email Domains

This configuration prevents users from signing in to social media websites with company email domains. Login Guard blocks sign-in attempts that use a company email domain.

To configure this:

Create a new policy for Login Guard and select Credentials as the policy type.

Screenshot%202026 07 18%20at%2000.20.40

Set the Social Media category action to Allow.

Screenshot%202026 07 10%20at%2014.41.42

Set Login Guard to Deny company email domains.

Screenshot%202026 07 10%20at%2014.16.01

Blocked Sign-In Message:

Screenshot%202026 07 14%20094949

Summary

Login Guard gives organizations control over which email domains users can use when signing in to websites. Admins can allow business-approved sign-ins for work tools while preventing company accounts from being used on personal or non-business websites.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013