WP Device Guard
00 · Statement

Right password.
Unknown laptop.
No entry.

WP Device Guard only lets /wp-admin open on machines you have approved. A password on its own stops being enough — so a leaked one stops being a breach.

  • Same login your team already uses
  • No VPN
  • Revoke in seconds
Access request yoursite.com/wp-admin
Account you@yourcompany.com
Password correct
Machine HW-UUID-DA6A98BB-2E74

The password is correct in every case. Only the machine changes.

01 · The check

Two things are checked, not one

WordPress already checks the password. Device Guard adds a second question — is this machine on the register? — and both must be satisfied before the admin opens.

Password Correct
Machine On the register
Admin opens
Password Correct
Machine Not registered
Refused
Password Wrong
Machine On the register
Refused
02 · Exposure

A password can travel. A machine can't.

Every common way a WordPress admin account is taken over ends the same way: someone who is not you, typing your password, on a machine that is not yours.

01

Phishing

A convincing login page collects working credentials. Without a registered machine, the credentials open nothing.

02

Credential reuse

A password from an unrelated breach is tried against your login within hours. Each attempt is refused before the password is even weighed.

03

Shared networks

Sitting on the same café or office connection as a registered laptop proves nothing. The register records machines, not networks.

03 · Procedure

Three steps, then nothing changes

Set up once. Afterwards your team signs in exactly as before — same page, same password, same habits.

01

Install the plugin

It starts in monitor mode, recording what it would have refused without locking anyone out while you watch.

You · once
02

Register the machines

Laptops run a small background app. Phones get a single-use link instead — open it, confirm the password, done.

Each person · once
03

Sign in as normal

Registered machine and correct password gets in. Anything else is refused and written to the ledger, with its reason.

Every day
04 · Revocation

Strike a machine off in seconds

Press revoke in your dashboard. The next request from that machine is refused — no password reset, no waiting for a session to lapse, no call to a network administrator.

Audit ledger extract
04:20:44loginallowedregistered machine
04:21:02revokeokby administrator
04:21:04loginrefusedmachine not trusted
04:36:10heartbeatrefusedrevoked

Genuine audit output. Revoke to lockout: two seconds.

05 · Register

Works with what your team already carries

Laptops prove themselves continuously in the background. Phones cannot run background apps reliably, so they prove themselves another way. You choose which methods the register accepts.

Accepted methods
Machine Proof Effort for the person
Mac · Windows · Linux Background app checks in every few minutes Installs once, then nothing
iPhone · iPad · Android Single-use authorization held in the browser Opens a link, confirms the password
Any phone · stronger Passkey held in the secure chip, non-exportable Face ID or fingerprint at sign-in
Managed fleet Certificate issued by your IT department None — invisible
06 · Scope

What it does not do

Device Guard proves a request came from a machine on the register. It is worth being precise about where that stops.

It is not antivirus. If a registered laptop is already compromised, the attacker is on a trusted machine. Device trust and endpoint security solve different problems.

It does not watch the keyboard. An unlocked, registered laptop in the wrong hands will work. Screen locks still matter.

It does not replace the password. Both checks run. Keep two-factor authentication switched on.

It guards the admin only. Other internal systems keep whatever protection they already have.

07 · In service

Make a stolen password useless

WP Device Guard is being trialled with its first sites. Get in touch if you would like to run it on yours.

Talk to us