Browse Docs
-
Introduction
-
Management
-
Deployment
- Deployment via RMM
- Operating System Agent
- Deployment via GPO
- Deployment via Intune
- VDI and Terminal Servers
- Windows Manual Deployment
- Mac MDM Deployment
- Mac Manual Deployment
- Network Deployment
- Secure Mobile Browser
- Bypass Option
- SaaS Restrictions
- Bookmark Manager
- Remote Uninstall
- Bulk Create Customers
-
Integrations
-
Nexi AI
-
Policy Management
-
Secure Access (ZTNA)
-
Auto Pilot
-
Training Videos
-
Questions & Answers
-
MSP Automation
ONLINE DOCUMENTATION
|
||||||
Login GuardIn this document
OverviewLogin Guard helps organizations control which email domains users can use when signing in to websites. When this feature is enabled, DefensX evaluates the email domain used during a website sign-in flow and applies the selected policy action. This allows organizations to either require users to sign in with approved company email domains or prevent the use of company email addresses on selected websites.
Email Domains page is used to define the approved company domains for Login Guard. These domains are then used by credential filter policies to allow or block sign-in attempts based on the configured Login Guard action.
How it worksLogin Guard has three available actions: No Act (Disabled): Applies no restriction. Allow only company email domains: Allows users to sign in only with the email domains configured under Email Domains. All other email domains are blocked. Deny company email domains: Blocks users from signing in with the email domains configured under Email Domains. Other email domains are allowed.
ConfigurationFirst, configure your company email domains. Navigate to Policies → Email Domains. Enter one or more company-owned domains in the Domains field, separating them with commas, semicolons, or line breaks; duplicate entries are ignored. Then click Save.
Next, enable Login Guard in the relevant policy. To do this, go to Policies → Policy Groups and click the Configure button on the relevant policy group.
Under Credential Filters, configure Login Guard by selecting the action that matches your needs: No Act, Allow only company email domains, or Deny company email domains.
Example ScenariosAllow only company email domainsScenario 1: Require Company Email Domains for ChatGPT Sign-InThis configuration allows users to sign in to ChatGPT only with approved company email domains. Login Guard blocks sign-in attempts that use a personal or unapproved email domain. To configure this: Create a Custom URL Group for ChatGPT.
Add the relevant ChatGPT domains to the Custom URL Group.
Then, create a new policy for Login Guard and select Credentials as the policy type.
In the relevant policy, set the Custom URL Group action to Allow.
Set Login Guard to Allow only company email domains.
Blocked Sign-In Message:
Scenario 2: Require Company Email Domains for AI Website Sign-InThis configuration allows users to sign in to AI websites only with approved company email domains. Login Guard blocks sign-in attempts that use a personal or unapproved email domain. To configure this: Create a new policy for Login Guard and select Credentials as the policy type.
Set the Artificial Intelligence category action to Allow.
Set Login Guard to Allow only company email domains.
Blocked Sign-In Message:
Deny company email domainsScenario 1: Prevent Sign-In to Reddit with Company Email DomainsThis configuration prevents users from signing in to Reddit with company email domains. Login Guard blocks sign-in attempts that use a company email domain. To configure this: Create a Custom URL Group for Reddit.
Add the relevant Reddit domain to the Custom URL Group.
Then, create a new policy for Login Guard and select Credentials as the policy type.
In the relevant policy, set the Custom URL Group action to Allow.
Set Login Guard to Deny company email domains.
Blocked Sign-In Message:
Scenario 2: Prevent Sign-In to Social Media Websites with Company Email DomainsThis configuration prevents users from signing in to social media websites with company email domains. Login Guard blocks sign-in attempts that use a company email domain. To configure this: Create a new policy for Login Guard and select Credentials as the policy type.
Set the Social Media category action to Allow.
Set Login Guard to Deny company email domains.
Blocked Sign-In Message:
SummaryLogin Guard gives organizations control over which email domains users can use when signing in to websites. Admins can allow business-approved sign-ins for work tools while preventing company accounts from being used on personal or non-business websites. |
||||||