On This Page
On This Page
Login as User
Overview
Investigate a member’s account experience without asking for their password or recreating the problem under your own administrator account. Login as User lets an authorized operator switch into an eligible WordPress user’s session from the Users list, review the site with that account’s access, and return through clearly visible switch-back controls.
Sessions have a configurable duration and a compact audit history. Administrator accounts, Multisite super admins, and users with protected capabilities cannot be impersonated, and the feature is unavailable during an active Temporary Login session. Login as User is a Pro module in WP PowerSuite, designed for controlled support access rather than unrestricted account switching.

- Agencies reproducing client-reported account and permission issues
- Support teams investigating an eligible customer’s or member’s experience
- Developers testing frontend and dashboard access for lower-privilege users
- Administrators who need timed user switching with a record of operator and target
Features
Switch From the Users List
Visible Switch-Back Controls
Time-Limited Sessions
Protected Administrator Accounts
Additional Target Restrictions
Impersonation Audit History
Authenticated Session Controls
PowerSuite Login Coordination
Use Cases
- Reproduce Member Access IssuesInvestigate why an eligible member sees a different page or account option from the administrator.
- Test Lower-Privilege RolesReview the experience of authors, subscribers, customers, or other eligible accounts during a site handover.
- Investigate Customer Account ScreensCheck the affected customer's account context without requesting their password.
- Track Support Account SwitchingKeep a record of which operator started a session, the target account, and how the session ended.
Frequently Asked Questions
Who can use Login as User?
Operators with the required site or network administrative capability. Developers can customize that operator capability, but target-account restrictions still apply.
Can I impersonate another administrator?
No. Administrator roles, Multisite super admins, and accounts with the protected high-privilege capabilities cannot be impersonated.
Can I remove the built-in blocked capabilities?
No. manage_options, manage_network, and edit_users always remain protected. You can add further capability restrictions.
How do I return to my account?
Use Switch back in the WordPress toolbar or the floating control available on the frontend and in wp-admin.
How long does an impersonation session last?
60 minutes by default. The setting accepts 5–1,440 minutes, and impersonation does not persist after expiry or logout.
Is the impersonated view read-only?
No. It is the target user’s actual session context, not a read-only preview. Actions available to that user can have their normal effects.
Does it bypass the target user's normal 2FA login?
Only the module’s authorized switching action receives the specific bypass. Ordinary logins are not given a general 2FA exemption.
Can I switch users from a Temporary Login session?
No. An active Temporary Login session prevents use of the impersonation feature.
What does the audit retain?
Recent impersonation events with operator, target, time, remote IP, and user agent. The default is 100 entries, adjustable from 10 to 500; the settings show the latest 25.
Does the audit trust X-Forwarded-For?
No. Its IP value uses REMOTE_ADDR, so a proxy’s address may appear depending on the server setup.
What happens when the module is disabled?
It records the module-disabled event and purges impersonation metadata. The module does not continue switching users without an active license.
Is Login as User free?
No. Login as User is a Pro module and requires an active WP PowerSuite license.


