Drupal is a registered trademark of Dries Buytaert
Release: Leaflet 10.4.11 Minor update available for module leaflet (10.4.11). Release: Session Inspector 1.0.8 Minor update available for module session_inspector (1.0.8). Release: Migrate QA 2.0.4 Minor update available for module migrate_qa (2.0.4). Release: CKEditor Description List 3.0.0 Major update available for module ckeditor_descriptionlist (3.0.0). Release: FlowDrop 2.4.0 Minor update available for module flowdrop (2.4.0). Release: JWT Token Refresh 1.0.4 Minor update available for module jwt_token_refresh (1.0.4). Release: ConReg 1.0.0-beta1 First beta version released for module conreg (1.0.0-beta1). Release: AI Image Studio 1.0.0-beta8 New beta version released for module ai_image_studio (1.0.0-beta8). Usage Milestone: Statistics Counter Module statistics_counter crossed 1,000 active installs. Module Revived: Decoupled Router 2.0.7 Module decoupled_router updated after 11 months of inactivity (2.0.7).

Guardian

174 sites Security covered
View on drupal.org

This module prevents users from logging in with a username and password directly. Instead, guarded users can only log in via a one-time login link generated by Drush or by using the password reset functionality. This helps secure accounts by avoiding the need to share or store passwords.

Guardian protects specified Users a.k.a. 'guarded users' from logging in with a username and password and changes to the login data (username or password).

To login with a guarded user, login is possible with drush uli [uid] or a password reset url.

In this way there will be no need to store and share complex passwords within your organization.

Installation

Developers

To install the module, make sure that the user 1 account has the correct mail address and that the mail address is the same as the init column in your user database table.

System Administrators

System administrators need to assign a shared inbox or group mail address for development teams to receive the password reset mail. If a person is leaving the project, only access to the webserver and the shared inbox needs to be denied to secure the website for user 1 access.

Usage

  • Use drush to request a one time login url: drush uli [uid]
  • Access the password reset form: /user/password

Activity

Tracked releases
1
Tracked since
Aug 2026
Latest release
1 week ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Release date
2.3.0 Stable Aug 10, 2026