Login in Browser Bypasses Admin-Pin

Server Version#: 1.42.2.10156
Player Version#: web-player

Situation:

  • I have a Plex Server
  • I have a Plex Pass
  • I share it with my Family
  • I have videos which can only be accessed by the Main Account
  • Main Account is secured with a Pin
  • Auto-Sign-in is disabled

Problem:

  • When i login in any Browser, it skips the Pin and logs into the Main Account
  • Kids now sees inappropriate content
  • In the Apps this doesn’t happen
  • Can’t use IOS App because its a pile of crap
  • When i create a second Plex Account, i need to pay for Premium a 2nd time
  • I need the Plex Pass for the additional Features.

How do i stop this from happening without buying a 2nd Plex Pass Subscription?

Plex DocumentationServer SettingsNetwork

Do you have any entries in Settings → Network → List of IP addresses and networks that are allowed without auth?

No auth = no access restrictions.

Any clients covered by those entries have admin level access to the Plex server.

1 Like

If you have managed users, YOU are supposed to make the login, then “Switch User” to the managed user account.
Don’t give out your plex credentials, ever.

1 Like

Thanks for the fast reply. There are no IP-Adresses there.
Do i have to put one there so the others dont get to bypass the Pin the first time they sign in with a new Browser?

You mean if i’m logging them in and then switch the user, they then need to use the Pin?

Do you know if there is a reason why this approach was chosen by Plex?

No. The default is to require authorization for all clients. Adding an IP address only permits that device to bypass auth.

1 Like

Only if they have a PIN of their own.
They must not know the PIN of the server admin.

If you enter the settings of the client before Switching User, you can activate “automatic logon”. This will always log in the Home user who was logged on last time, before the client was closed.
If we are talking about a web browser as a client, don’t forget to tell it to NOT delete the cookies from plex.tv when it’s closed.

1 Like

You mean that you are logged in as admin after logging in as admin? Well I think, thats fairly reasonable, isn’t it?

A suggestion if you often logon new devices or even would like to allow other people logging on your Home devices (without them getting access to all libraries and to know your admin credentials) would be to just add another Full Plex Account to your Plex Home (with also limited library access).

Use that user to logon your devices then.
I use that approach and never use my admin user to logon any home devices.