Plex Server Security: How to Lock Down Your Server
If your Plex server is accessible from the internet, it’s a target. Default settings leave several doors open that should be closed.
Authentication
- Enable two-factor authentication on your Plex account (plex.tv > Account > Two-Factor Authentication). If someone gets your password, 2FA stops them
- Require authentication for local network: Settings > Network > set “List of IP addresses and networks that are allowed without auth” to EMPTY. Default lets anyone on your LAN access everything
- Review Managed Users: remove accounts you don’t recognize. Check Home Users and Friends lists regularly
Network
- Use a non-default port. Change from 32400 to something random (40000–65000). Reduces automated scanning
- Enable Secure connections: Settings > Network > Secure connections > Required. Forces HTTPS
- Restrict LAN access: only allow your actual LAN subnet, not 0.0.0.0/0
- Consider a reverse proxy: Nginx Proxy Manager or Caddy adds an SSL layer and hides your actual server
Server Updates
Plex has had real security vulnerabilities (CVE-2020-5742, CVE-2023-XXXXX). Keep your server updated. Enable auto-update or check weekly. An unpatched Plex server with remote access is an invitation for exploitation.
OS-Level Security
- Run Plex under its own user account, not root/admin
- Set media folder permissions to read-only for the Plex user
- Keep the host OS updated
- Use a firewall (UFW on Linux, Windows Firewall) to allow only necessary ports
Minimum security: 2FA + HTTPS required + non-default port. Takes 10 minutes and prevents the most common attacks.