Skip to content
  • Pricing
  • Products & Services
      Save 25%

      Solid Suite

      Secure your sites, keep them safely backed up, and grow your business… all while saving time and money.

      • Solid Security
      • Solid Backups
      • Solid Central
      • Solid Academy
      See pricing

      Protect

      Shield your site from cyberattacks and prevent security vulnerabilities

      A cloud-first solution for rocket fast backups and one-click restore.

      Repair

      Hacked website? Let our WordPress security experts clean up malicious code, remove threats and restore your site.

      Manage

      Maximize and amplify your admin with remote multi-site management.

      Ensure delivery of every email sent from your site.

      Free Plugins

  • Resources
      Save 25%

      Solid Suite

      Secure your sites, keep them safely backed up, and grow your business… all while saving time and money.

      • Solid Security
      • Solid Backups
      • Solid Central
      • Solid Academy
      See pricing

      Academy

      Solid Academy

      For anyone who wants to start or grow a business around WordPress.

      Guides

      Dive deeper into our free WordPress and business guides.

      Livestreams

      Free livestreams to help you discover new tools and work more efficiently

      Tutorials Academy

      Learn WordPress with our beginner WordPress tutorials

      Resources

      Blog

      Catch up on the latest news from our WordPress security experts

      Vulnerability Report

      Keep track of every new plugin and theme vulnerability

      Support

      Your success with Security, Backups and Central is our highest priority.

      Documentation

      Learn everything you need to know about our products & services.

Sign In Get Solid Suite
SolidWP Logo Black
  • Pricing
  • Products & Services
    • Solid Security Pro
    • Solid Backups — NextGen
    • Solid Fix
    • Solid Central
    • Free Plugins
    • Solid Security
    • Solid Performance
    • Solid Mail
  • Resources
    • Solid Academy
    • Guides
    • Livestreams
    • Tutorials
    • Blog
    • Vulnerability Report
    • Support
    • Documentation

How It Works

17
  • All About Solid Security’s Tools
  • Using Solid Security’s CAPTCHA
  • All about Firewall with Solid Security
  • Solid Security Two-Factor Authentication (2FA) Settings Guide
  • Releasing Site Lockouts in Solid Security
  • Diagnosis Tips: Raw Details of Site Scanner Logs
  • SolidWP Licensing: How to Make sure your site is licensed correctly
  • All about Solid Security’s Debug Mode
  • Frequently Asked Questions
  • Vulnerability Protection with Solid Security
  • Security Logs
  • All about User Security with Solid Security
  • All about Solid Security Site Scans
  • Solid Security Dashboard
  • What are Passkeys for WordPress Websites?
  • All about the Solid Security Settings
  • Understanding Trusted Devices in Solid Security

Learn More

9
  • Restrict Admin Access by Country Settings Guide
  • Security Headers Settings Guide
  • List of Solid Security Pro Action Hooks
  • How Do I Integrate My Plugin with Solid Security Pro reCAPTCHA?
  • Solid Security Pro WP-CLI Integration
  • All about Solid Security’s Debug Mode
  • Frequently Asked Questions
  • What are Passkeys for WordPress Websites?
  • Understanding Trusted Devices in Solid Security
View Categories
  • Home
  • SolidWP Documentation
  • Solid Security
  • Learn More
  • Restrict Admin Access by Country Settings Guide

Restrict Admin Access by Country Settings Guide

5 min read


Stolen admin credentials can be exploited by foreign threat actors to gain access to a website to further their goals. Restrict Admin Access by Country enhances the security of your WordPress dashboard by limiting administrative logins to a specific list of approved countries.

How It Works #

Solid Security now provides a simple interface to restrict admin access to a list of approved countries. When enabled, this feature checks the geolocation of the IP address used for any administrative login attempt. If the country is not on your authorized list, access is denied immediately, preventing attackers from using stolen credentials from foreign locations.

Configuring Your Authorized Countries #

To enable this feature, navigate to Settings > Features in your WordPress dashboard. Locate the Restrict Admin Access by Country setting and toggle it on.

Once enabled, expand the section to reveal the Authorized Administrator Countries setting.

This setting allows you to define all countries from which admin login requests should be permitted. Simply search for and select the countries where your administrators reside or travel to frequently.

Defensive Logic: Saving Your List #

To prevent you from accidentally locking yourself out, defensive logic has been added to the settings page. Solid Security will notify you if you attempt to save a list of countries that does not contain your current country, based on the geolocation of your current IP address.

Authorizing IP Addresses #

There may be scenarios where an administrator needs to log in from a country not on the authorized list (e.g., using a VPN with a static IP or traveling temporarily). You can circumvent the country check for specific users by adding their IP address to the Authorized IPs list in Solid Security settings.

Defensive Logic: Removing IPs #

Similar to the country list, defensive logic protects you here as well. If you attempt to remove your current IP address from the Authorized IPs setting, and your geolocated country is not in the list of Authorized Administrator Countries, the plugin will alert you to prevent a potential lockout.

What Happens During an Unauthorized Attempt? #

If an attacker (or an admin using an unapproved VPN) attempts to log in from an unauthorized country, the following occurs:

  1. Access Denied: A generic denial notice is issued to the user.
  2. Logging: Every failed attempt generates a Warning level entry in the Solid Security logs, allowing you to audit these attempts.
  3. Brute Force Lockout: If an admin account repeatedly attempts to log in from an unauthorized country, Solid Security’s Brute Force feature will trigger. Because the access denial re-uses existing access control functionality, the offending IP address will be blocked after numerous failed attempts.

Order of Execution #

When a login occurs, Solid Security processes access control logic in the following order:

  1. Captcha
  2. Restrict Admin Access by Country
  3. Trusted Devices

Improving Geolocation Accuracy #

To improve the accuracy and reliability of the geolocation data used by this feature, we strongly recommend that customers sign up for and configure one of the MaxMind APIs. You can reference these in Settings > Features > Utilities.

Note: customers should be mindful that admin users logging in behind a VPN may have their access denied if the VPN’s IP address is geolocated to an unauthorized country. If your VPN uses static IP addresses, we recommend adding them to the Authorized IPs setting to ensure consistent access.

What to Do If You Get Locked Out #

Even with defensive logic in place, it is possible to accidentally lock yourself out of your site—for example, if you unexpectedly need to log in while traveling to an unauthorized country, or if your VPN assigns you a new IP address. If you find yourself locked out, don’t panic.

The fastest and most reliable way to regain access to your dashboard is by using our emergency bypass constant. You can temporarily disable the country restriction check by adding the ITSEC_DISABLE_COUNTRY_RESTRICTION constant to your site’s wp-config.php file.

Here is how to apply the bypass:

  1. Access your site’s files using FTP/SFTP or your hosting provider’s File Manager.
  2. Locate and edit the wp-config.php file found in the root directory of your WordPress installation.
  3. Add the following line of code just above the /* That's all, stop editing! Happy publishing. */ line:
    define( 'ITSEC_DISABLE_COUNTRY_RESTRICTION', true );
  4. Save the file and refresh your WordPress login page. The country restriction will be bypassed, allowing you to log in normally.

Once you have successfully logged back into the dashboard, navigate to Settings > Features > Restrict Admin Access by Country to correct your authorized countries or add your current IP address to the Settings > Global > Authorized IPs list. After fixing your configuration, be sure to remove the constant from your wp-config.php file so the feature can resume protecting your site.

Magic Links and Access Control #

It is important to note that logging in with a valid Magic Link generated by Solid Security will bypass the Restrict Admin Access by Country check.

Because Magic Links are designed to provide secure, verified, and seamless access, they inherently bypass this and all other access control features. This ensures that users with a valid, authenticated link can always access their accounts, regardless of their current physical location or IP address.

Conclusion #

The Restrict Admin Access by Country feature provides a significant additional layer of security. While there is some functional overlap with Trusted Devices, they work best when used together:

  • Trusted Devices identifies logins from unrecognized devices and downgrades access to prevent damage.
  • Restrict Admin Access by Country denies access entirely at the door if the location is incorrect.

Ideally, customers should enable both features. However, if you choose not to use Trusted Devices, we highly recommend enabling Country Restriction to reduce the attack surface of your site.

Updated on April 22, 2026

Was this doc helpful?

  • Happy
  • Normal
  • Sad
Security Headers Settings Guide
Table of Contents
  • How It Works
  • Configuring Your Authorized Countries
    • Defensive Logic: Saving Your List
  • Authorizing IP Addresses
    • Defensive Logic: Removing IPs
  • What Happens During an Unauthorized Attempt?
    • Order of Execution
  • Improving Geolocation Accuracy
  • What to Do If You Get Locked Out
  • Magic Links and Access Control
  • Conclusion
SolidWP
  • Pricing
  • Products
    • Solid Suite – save 25%
    • Solid Security
    • Solid Backups — NextGen
    • Solid Central Pro
  • Resources
    • Blog
    • Academy
    • Guides
    • Tutorials
    • Vulnerability report
  • Support
    • Documentation
  • My account
  • Contact us
    • Terms
    • Refund policy
    • Privacy policy
    • Change Cookie Preferences
  • About SolidWP
    • FAQ
    • Looking for iThemes?
    • Affiliates
    • Press
  • Our Partner Brands
    • GiveWP
    • Iconic
    • KadenceWP
    • LearnDash
    • MemberDash
    • Orderable
    • The Events Calendar

Get Solid Suite bundled with hosting.

Explore StellarSites
  • X
  • YouTube
  • Facebook

A Liquid Web Brand
Hosting for WordPress
© 2025 All Rights Reserved

StellarWP logo
Liquid Web logo