Security features
Learn about the LogMeIn Rescue security features.
The LogMeIn Rescue security features include a number of components that enhance the security and protection of your account. The security features can be purchased as a security add-on, which includes all the features. Following that, customers can enable any or all of the features.
For a high-level representation of the security features, see Overview of security features.
IP-based restricted access
If the Restricted Access Package is enabled, LogMeIn Rescue filters the IP addresses, allowing technicians and customers to establish LogMeIn Rescue sessions only with previously configured networks.
- Technician restriction: Creates a restriction that allows technicians to support customers only within a specified IP range.
- Customer restriction: Creates a restriction that allows customers within a specified IP range to receive support only from a specified LogMeIn Rescue account. This is an ideal choice of defense against malicious attacks from other LogMeIn Rescue accounts.
- Login restriction: Creates a restriction that allows technicians to sign in only within a specified IP range.
How it works
IP filtering can only be set by GoTo.
For technicians, access to individual networks is opened by configuring a range of IP addresses with which the technicians can establish a session. This will prevent a technician from establishing a LogMeIn Rescue session if they are outside the pre-approved IP range.
For customers, services can be configured to restrict them to establishing a LogMeIn Rescue session only with technicians of a specified account. This prevents the initiation of sessions with anyone outside that LogMeIn Rescue account.
Device-based restricted access
If the Restricted Access Package is enabled, the DRAP component allows starting remote support sessions only from the LogMeIn Rescue account that generated the installer. This ensures endpoint security for both corporate and BYOD devices.
How it works
When an approved technician initiates a LogMeIn Rescue connection:
- The LogMeIn Rescue applet checks for DRAP installation.
- If installed, DRAP validates the company secret.
- Upon successful validation, the connecting account is identified and the session starts.
Enterprise domain
With this feature, you can have a completely separated domain from the standard LogMeIn Rescue domain. This feature allows customers to access a dedicated enterprise domain while blocking the standard logmeinrescue.com domain used by non-enterprise and trial users.
How it works
Enterprise domain can be set if the customer meets the criteria of being an enterprise customer. Therefore, they need to be considered as an Enterprise account by GoTo, and have a LogMeIn Rescue Enterprise account.
To be considered an Enterprise account, customers must meet a certain financial threshold, be assigned a Success Representative, and be vetted as a valid business. If you would like to enable the enterprise-specific domain, contact your Success Representative.
- What to do if you don't qualify for the Enterprise domain, but you need it enabled for another reason crucial to your business
- GoTo will review requests to be considered for the Enterprise domain on a case by case basis. Contact GoTo support for further information.
Company PIN code validation
This feature is suited for organizations that use the LogMeIn Rescue PIN Entry Form on their website. Company PIN code validation protects the PIN entry point, ensuring that only PIN codes generated by a specified LogMeIn Rescue account are accepted. Similarly, this protection extends to the Calling Card, making sure that PIN codes generated by other LogMeIn Rescue accounts are not accepted.
This protection ensures that a malicious caller fails when they are trying to trick a customer into starting a LogMeIn Rescue session.
How it works
The company PIN code validation feature needs to be enabled by GoTo. Once it is enabled, a unique company hash code can be found at in the Custom Logmein123.com form script input as an additional line of code.
Allowed hosts for external PIN entry
This feature limits LogMeIn Rescue PIN entry to a set of self-hosted PIN entry sites defined in the Administration Center. If a PIN code generated on a LogMeIn Rescue account is entered on a PIN entry point that is hosted on a different, alternate domain, a rejection message appears. If the PIN code is entered on logmein123.com, the customer is automatically re-directed to the self-hosted PIN entry site.
With this security feature, GoTo ensures high-level protection for the customer if they accidentally visit a malicious domain that can cause damage to their device or environment. It also makes sure that customers are using the correct PIN entry point.
How it works
The company PIN code validation feature needs to be enabled by GoTo. Once it is enabled, the administrator can configure a new host URL for the PIN code entry page at .
Company ID validation for Calling Cards
This feature ensures that a calling card can only connect to and accept a remote support session initiated from the account where it was generated and installed.
How it works
Using this feature, administrators can generate calling card installers that always check whether the connecting party has the same company ID as the calling card installer. If the ID of the connecting party does not match the ID of the calling card, the connection is not established.
This feature can be set at the
checkbox.Account name filtering
When creating a new account, customers might choose a company name that already exists in the LogMeIn Rescue registry. The account name filtering feature checks the company name that is created at a new account registration or renaming process, and ensures that no duplicate entries are present in the registry.
If you need to change the company name of your account, contact your Customer Care representative.
9-digit-long PIN sessions
LogMeIn Rescue introduces an update to the 6-digit-long PIN sessions that, combined with the PIN code validation time-out feature, offers a strong security solution against potential brute force attempts.
How it works
PIN codes are securely generated using a cryptographic algorithm. Once a connection is established using a 9-digit PIN code, or the connection does not take place due to session time-out, the PIN code is invalidated by LogMeIn Rescue to prevent its further use.
A PIN code's validity time-out can be set at the Set time-outs and warnings.
. Learn more about time-outs at