Introduction
This bundle delivers a powerful suite of Security Modules for Perfex CRM, built to give administrators more control, compliance, and visibility. Each module is lightweight, easy to configure, and seamlessly integrates into Perfex CRM without disrupting your existing workflow.
From stronger password policies and precise login monitoring to geo-based restrictions and advanced activity tracking — these tools help you safeguard your system, improve accountability, and simplify administration with minimal effort.
- Account Controls – Restrict logins by time of day, day of week, or specific devices. Apply rules individually or in bulk for both staff and customers.
- Extended Activity Log – Capture every critical action in Perfex CRM with detailed logs including reference, module, IP address, device, and browser details. Includes powerful filters and a one-click clear option.
- GeoIP Restriction – Secure accounts with IP, email, country, state, city, pin-code based blocking or whitelisting. Switch easily between blacklist and whitelist mode, with built-in VPN detection.
- Password Rotation – Enforce password rotation policies with custom frequency, strong password validation, reminders before expiry, and automatic account lockout when expired.
- Login Log – View complete login and logout history with duration, device, browser, and IP details. Includes deep filtering for analysis and a quick-clear option.
- Login Attempt – Limit failed login retries, enforce lockout times, and block accounts after repeated failures. Automatic cooldowns reset after 24 hours, with admin override for blocked accounts.
- Login Session – Monitor all active user sessions in real time. Force logout remotely, apply temporary login bans, or enforce single-login per user with automatic timeout for inactive sessions.
System Requirements
- Perfex CRM v3.1.0 or higher
Account Controls
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the account_controls.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the account_controls.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Usage :
- Time Restrictions
-
- Define allowed login hours for staff and customers (e.g., 09:00 – 17:00).
- Any login attempt outside the configured time window will be denied access.
- Day Restrictions
-
- Restrict access on specific days (e.g., Sundays).
- Users attempting login on blocked days will be denied access.
- Device Restrictions
-
- Restrict logins based on device type or operating system (e.g., block Linux or mobile devices).
- Ensures only approved environments can access the system.
- Individual User Settings
-
- Apply restrictions separately for each staff member or customer.
- Fine-grained control ensures that security policies can be customized per user.
- Bulk Updates
-
- Update restrictions for multiple users at once for faster management.
- Ideal for applying organization-wide security policies in a single action.
- Admin Control
-
- Admins can reset user passwords immediately if security concerns are identified.
- Overrides allow admins to quickly unblock or reconfigure account restrictions when needed.
Extended Activity Log
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the extended_activity_log.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the extended_activity_log.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Usage :
- Activity Tracking
-
- The module automatically records all important actions performed in Perfex CRM.
- Each log entry includes details such as:
- Reference (linked record or entity)
- Module name where the action occurred
- Action performed (create, update, delete, login, logout, etc.)
- User’s IP address
- Device and browser information
- Timestamp of the activity
- Log Management
-
- View detailed logs with structured columns for quick analysis.
- Use the Quick Clear Log button to instantly clear all records if needed.
- Advanced Filters
-
- Filter activity logs with multiple parameters such as:
- Date range
- User
- Module
- Filter activity logs with multiple parameters such as:
GeoIP Blacklist
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the geoip_blacklist.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the geoip_blacklist.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Usage :
- Blacklist Mode
-
- Add IP addresses, emails, or countries to the blacklist.
- Any user matching the entries will be blocked from accessing the system.
- Custom error message is displayed when blocked.
- Wishlist Mode
-
- Add IP addresses, emails, or countries to the wishlist.
- Only users matching the entries will be allowed to access the system.
- All other users will be denied access automatically.
- Country Listing
-
- All countries are pre-listed for easy selection and entry.
- Admins can quickly block or allow access for entire regions.
- VPN Detection
-
- Enable or disable VPN usage for system access.
- When disabled, login attempts from VPNs are automatically blocked.
- Quick Toggle
-
- Switch between Blacklist mode and Wishlist mode with a single click.
- Provides flexible access control without reconfiguring database entries.
Password Rotation
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the password_rotation.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the password_rotation.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Configuration :
Once the module is installed and activated, you'll see three options, Deactivate and Settings. Click on the Settings button to quickly access the Password Rotation Settings
Alternatively, you can navigate to Setup → Settings → Password Rotation to access its configuration options, which include :
- Customer Frequency (In Days) – Customer will have to change password on every number of days, Example 60 (Customer will not able to keep same password for 60 days, They have to update it before timespan or account will be locked which can be approved by admin)
- Staff Frequency (In Days) – Staff will have to change password on every number of days, Example 60 (Staff will not able to keep same password for 60 days, They have to update it before timespan or account will be locked which can be approved by admin)
- Strict Validation – When updating password user will have strong password requirements, Requires 1 special character, 1 capital letter, 1 small letter, 1 number and Minimum length of 8 characters
- Enable for Staff – When disabled, password rotation process will be not applied to staff.
- Enable for Customer – When disabled, password rotation process will be not applied to customer.
Usage :
- Password Expiry & Rotation
-
- Admin defines separate password rotation frequency (in days) for staff and customers.
- Each user’s password expiry date is automatically calculated based on this frequency.
- Users are required to update their password before the expiry date to maintain access.
- Strict Validation Rules
-
- Admin can enable or disable Strict Validation for new passwords.
- When enabled, passwords must contain:
- At least 1 special character
- At least 1 uppercase letter
- At least 1 lowercase letter
- At least 1 number
- Minimum length of 8 characters
- Password Expiry Alert
-
- Users receive an in-app alert 5 days before their password expires.
- A forced in-app alert reminder is sent 3 days before the expiry date.
- If users still do not update their password, their account will be locked upon expiry.
- Locked Accounts
-
- If a password expires without being updated, the account is locked for security.
- Locked users can request a password reset.
- Alternatively, admins can directly reset the password from the admin panel.
- Admin Management
-
- Admins can view and manage all user password expiries from the settings panel.
- Admins can reset user passwords manually if required.
- Admins can approve or reject password reset requests submitted by users.
Login Log
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the login_log.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the login_log.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Usage :
- Login & Logout Tracking
-
- Each login attempt is recorded with corresponding logout time.
- Session duration is automatically calculated for better insights.
- Detailed Session Information
-
- Logs include IP address, device type, and browser details.
- Enables quick detection of unusual login patterns or suspicious devices.
- Advanced Filtering
-
- Use deep filters to narrow down results by user and date range.
- Provides clear visibility for auditing and security analysis.
- Quick Log Management
-
- Admins can clear logs instantly with a single click.
- Ensures database optimization and removes unnecessary history when required.
Login Attempt
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the login_attempts.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the login_attempts.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Configuration :
Once the module is installed and activated, you'll see three options, Deactivate, Manage and Settings. Click on the Settings button to quickly access the Login Session Settings
Alternatively, you can navigate to Setup → Settings → Login Attempt to access its configuration options, which include :
- Enable for Staff
- Enable for Customer
- Allowed Retries Before Lockout - User will have to face lockout time and will not able to login or retire for that time
- Lockout Time (In Minutes) - The user will be temporarily locked out from retrying, and with each failed attempt, the lockout duration will be multiplied.
- Maximum Lockout - Maximum number of allowed lockouts per user. If this threshold is exceeded, login access will be restricted until approved by an administrator.
Usage :
- Enable / Disable Module
-
- Admins can independently enable or disable login attempt protection for staff and customers.
- Allowed Retries Before Lockout
-
- Defines the number of failed attempts before triggering a lockout (e.g., 3 failed tries).
- Once the threshold is reached, the user cannot attempt login until the lockout period ends.
- Lockout Time (in Minutes)
-
- Specifies the base duration of the lockout period.
- Lockout time increases with each repeated lockout, multiplied by the number of lockouts (e.g., 1st lockout = 3 mins, 2nd lockout = 6 mins, 3rd lockout = 9 mins, etc.).
- Maximum Lockouts
-
- Limits the total number of lockouts allowed per user.
- If exceeded, the account is fully locked, and login access is restricted until manually approved by an administrator.
- Automatic Reset
-
- Failed attempts and lockout counts resets after 24 hours.
- Blocked accounts, however, remain locked until explicitly approved by the administrator.
- Admin Management
-
- Admins can view a list of users whose accounts are locked.
- From the admin panel, login access can be re-enabled with a single action.
Login Session
Installing the module is quick and simple, It takes just a few minutes :
- Extract the main .zip file and locate the login_session.zip file.
- Log in to the Perfex CRM admin panel as an administrator and go to Setup → Modules.
- Click Choose File and select the login_session.zip
- Click Install to complete the process.
Once the module is installed, it will appear in the list of available modules below. Simply click the Activate button to enable it.
Configuration :
Once the module is installed and activated, you'll see three options, Deactivate, Manage and Settings. Click on the Settings button to quickly access the Login Session Settings
Alternatively, you can navigate to Setup → Settings → Login Session to access its configuration options, which include :
- Enable for Staff – If enable staff will only able to login from single device.
- Enable for Customer – If enable customer will only able to login from single device.
Usage :
- Session Tracking
-
- Each login session records user details, IP address, browser, device, and login time.
- Admins can view a complete list of currently logged-in staff and customers.
- Force Logout
-
- Admins can immediately terminate any user’s active session.
- Once logged out, the user is redirected to the login page.
- Temporary Ban
-
- In addition to logout, admins can apply a temporary ban on a user account.
- The ban prevents the user from re-logging in for a defined duration (in minutes).
- After the ban period ends, login access is automatically restored.
- Single Login Restriction
-
- If enabled by the admin, Staff or Customer is allowed only one active session at a time.
- If the user tries to log in on a new device or browser while already logged in, the new session will be rejected.
- If the user closes the browser without logging out, the session will automatically expire after 30 minutes of inactivity, allowing login from another session.
Support
For support, please reach out to us at codeonstring@gmail.com. We will respond as soon as possible, typically within one working day.
Changelog
VERSION 1.0.0 – Initial Release