Skip to main content

Security Center

Learn how to manage profile security, account protection, and web access restrictions for your team.


I. Introduction to Security Center


Security Center is the unified security management hub for your team. It brings together three core capabilities: profile security settings, member account security management, and team web access restrictions. Instead of configuring security across separate modules, you can maintain all rules in one place. Strengthen browser profiles, manage account risks for team members, and control web access to build protection across profiles, people, and access, reducing business risks caused by mistakes, data leaks, and unauthorized access.


II. Profiles & Accounts


1. Account Security

Two-Factor Authentication

When two-factor authentication (2FA) detects an unusual login, identity verification via an authenticator app or email is required. This feature is available in V2.8.0 and later.

Verification level: Low

Two-factor authentication is required when signing in on a different device or when more than 90 days have passed since the last two-factor verification.

Verification level: Medium

Two-factor authentication is required when signing in on a different device or when more than 30 days have passed since the last two-factor verification.

Verification level: High

Two-factor authentication is required every time you sign in to the client.

Login IP Control

When enabled, only IP addresses or IP ranges entered in the allowed range can sign in to MoreLogin.


2. Password Protection

Password protection includes Basic Protection and Advanced Protection. Administrators can lock these settings separately for the Super Admin, Admin, Manager, and Employee roles to restrict high-risk actions, prevent password leaks and data extraction, and protect team account assets.

Basic Protection

Basic Protection includes two controls that can be locked independently for different roles.

  • Prevent viewing passwords saved in profiles

  • After locking, controlled roles cannot view account passwords saved in browser profiles through the password manager, preventing plaintext password exposure.

  • Prevent using developer tools

  • After locking, the corresponding roles cannot open browser DevTools through shortcuts or menus, preventing the extraction of page data, cookies, and other sensitive information.

Advanced Protection

  • Prevent external password reading/export

  • After locking, controlled roles cannot use extensions or scripts to read or export passwords saved in profiles, further preventing password leaks.

Limitation: This feature only supports profiles using Chrome kernels 138–144.

Note:

1. Locking may reduce profile startup speed.
2. For more comprehensive password protection, we recommend also locking the corresponding role’s Basic Protection permissions.

Lock/Unlock (available in client V2.48.0 and later)


3. End-to-End Profile Encryption

Key settings: After setting a private key for profiles, you can enable 【End-to-End Encryption】 for selected profiles. The setting only applies to profiles with encryption enabled. See the screenshot below for how to enable profile encryption.

Path: Create Profile > End-to-End Encryption (requires V2.8.0 or later).

a. Verify once after signing in on a new device: After signing in on a new device, verification is required the first time you open a profile. Subsequent launches of encrypted profiles do not require verification.

b. Verify once after each login: After each login to the MoreLogin client, verification is required the first time you launch an encrypted profile. Subsequent launches do not require verification.

c. Verify every time a profile is launched: Key verification is required every time an encrypted profile is launched.


4. Extension Data Protection

Local extension data protection: When a profile starts, the local data files of standard extensions are automatically encrypted to prevent unauthorized access.


III. Web Restrictions


Web Restrictions includes URL Access Restrictions and Web Element Restrictions to manage web activity in team browser profiles. Administrators can configure allowlists and blocklists and hide sensitive page elements, helping prevent access to risky sites and business data leaks while improving overall team security.

1. URL Access Restrictions

URL Access Restrictions lets you define websites that are blocked or exclusively allowed, controlling the browsing scope of team browser profiles. Blocklist and allowlist modes can block risky sites, restrict unrelated websites, prevent account and information leaks, and improve business security.

1.1 Create a URL Access Restriction Policy

  • Go to 【Security Center】 > 【Web Restrictions】 > 【URL Access Restrictions】, click 【Create Now】, and the New Policy window will open.

  • Complete the basic information on the left:

    • Policy Name (required): Name the access policy, up to 50 characters, so rules can be easily distinguished.

    • Applicable Members (required): Select the team roles or members to which the policy applies.

    • Applicable Profiles (required): Specify the browser profiles to which the rule applies.

    • Policy Description (optional): Add a note describing the policy’s purpose, up to 400 characters.

  • Configure the URL access mode and applicable URLs on the right:

    • Block Access (blocklist mode): Only URLs entered in the list are blocked; all other websites remain accessible. This is suitable for blocking phishing, data-leak, and risky sites.

    • Allow Access Only (allowlist mode): Only URLs entered in the list are allowed; all other webpages are blocked. This is suitable for strict work scenarios where only business sites are available.

    • Applicable URL (required): Enter a complete URL beginning with http:// or https://. Enter multiple URLs on separate lines, one per line. Wildcards * are supported for domain matching, for example: https://*.example.com/*. Maximum length: 5,000 characters.

  • After completing all settings, click 【Confirm】 to save the policy.

    ⚠️ After saving the policy, restart the corresponding browser profiles for the access restriction rules to take effect.

1.2 Reset/Edit an Existing URL Access Policy

  • Find the target policy in the URL Access Restriction policy list and click 【Edit】.

  • In the edit window, you can change the policy name, applicable members, applicable profiles, and policy description.

  • You can switch the URL access mode and add, remove, or edit the applicable URL list.

  • Click 【Confirm】 to save the changes.

  • You must restart the controlled browser profiles for the updated rules to take effect.

1.3 Delete a Policy

Click Delete in the list to remove the URL access rules. The corresponding profiles will no longer apply the blocking logic.

💡 Important Notes

  • In allowlist mode, all websites not entered in the list are blocked. Make sure all required business sites have been added.

  • The policy can apply to both local fingerprint browser profiles and Cloud Browser profiles.

  • URLs must use the complete format. Use the wildcard * to match subdomains and subpaths


2. Web Element Restrictions

Web Element Restrictions can precisely hide specified DOM elements on webpages, such as phone numbers, email addresses, QR codes, keys, and other sensitive content. Hidden content remains invisible even when members take screenshots or record their screens, enabling fine-grained access control.

2.1 Create a Web Element Restriction Policy

  • Go to 【Security Center】 > 【Web Restrictions】 > 【Web Element Restrictions】, click 【Create Now】, and the New Policy window will open.

  • Complete the basic policy information:

    • Policy Name (required): Name the policy, up to 50 characters, so multiple rules can be easily distinguished.

    • Applicable Members (required): Select the team roles or members to which the policy applies.

    • Applicable Profiles (required): Specify the browser profiles to which the policy applies.

    • Policy Description (optional): Add a note describing the policy’s purpose, up to 400 characters.

  • Capture the web elements to hide.

  • Click 【Start Capturing】 in the upper-right corner. On the target webpage, click the sensitive elements you want to hide. The system automatically captures their selectors.

  • Return to the window, review the captured element list, and click 【Confirm】 to save the policy.

After saving, restart the corresponding browser profiles for the policy to take effect.

2.2 Reset/Edit an Existing Web Element Restriction Policy

To change hidden elements or the applicable scope, reconfigure the existing policy:

  • Find the target policy in the Web Element Restriction list and click 【Edit】.

  • In the edit window, you can change the policy name, applicable members, applicable profiles, and policy description.

  • Recapture web elements: click 【Start Capturing】 and select the target elements again. You can remove old captured items and add new elements.

  • Click 【Confirm】 to save the changes.

  • ⚠️ Important: After modifying the policy, restart the controlled browser profiles for the new settings to take effect.

2.3 Delete a Policy

If the policy is no longer needed, click Delete in the list. The corresponding profiles will no longer apply element-hiding rules.

Conflict Rule Details

When rules in multiple policies conflict, they are merged as follows:

1. Block Access takes priority over Allow Access Only.

If the same URL appears in both the blocklist and allowlist, access will be blocked.

2. If a website is blocked, its Web Element Restrictions do not apply.

If the entire website is blocked, configured Web Element Restrictions on that website will not be executed.


Need more help? Contact us:


Did this answer your question?