Get Device Guard
One plugin on the website, one small app on each computer. Install both, and only registered machines reach wp-admin — with no VPN.
macOS installer
Double-click the installer and follow it — the app lands in Applications and starts keeping this Mac trusted. If macOS warns that the developer is unverified, open System Settings → Privacy & Security and choose Open Anyway, once.
Windows app
One file, nothing to unzip. Double-click ClassisDeviceGuard.exe; if SmartScreen warns, choose More info then Run anyway. It installs itself, shows your device ID, and adds a shield to the system tray.
WordPress plugin
The gate itself. In wp-admin, go to Plugins → Add New → Upload Plugin, choose this file, then Activate. It installs as a must-use plugin and cannot be switched off without a release code.
Before you install. These are pilot builds. The apps are not yet code-signed, so macOS Gatekeeper and Windows SmartScreen will warn once on first launch — that is expected. They are pre-configured for this site (wpdeviceguard.com). Install the plugin first and register your device before switching the gate to enforce.
To remove. macOS: run the macOS uninstaller. Windows: run the Windows uninstaller.