Moodle Restrict Access: How Conditional Activity Rules Work and Where They Break
Moodle's Restrict access gates activities behind per-user rules (completion, grade, date, group, profile). It shows items greyed‑out or hidden, works with All/Any logic, and is a design aid, not a security boundary.
21 Aug 2025, 05:39 UTC

What Restrict Access Actually Does
Moodle's Restrict access feature (still called Conditional activities in older docs) lets you gate an activity or resource behind rules that evaluate each viewer's own state. A quiz can stay invisible until a student completes a prerequisite assignment, or a forum can open only after a specific date for members of a particular group. The rules live inside each activity's settings, not on a site-wide screen, and they are evaluated at view time for the current user.
The practical takeaway: Restrict access is a course-design aid, not a security boundary. Users with editing or grading capabilities in the course normally see restricted items regardless of rules. If you need to protect confidential material, use enrolment methods and role permissions instead.
How the Mechanism Works
When a user loads a course page, Moodle checks every activity that has Restrict access rules. For each rule it compares the user's data—completion records, gradebook scores, group memberships, profile field values, the current date/time—against the configured condition. Rules can be combined with All (every rule must match) or Any (at least one rule matches) logic, which is how simple branching paths are built.
Each rule also carries a visibility setting:
- Show activity greyed-out, with restriction information — the learner sees the item, reads why it's unavailable, and knows what to do next.
- Hide activity entirely — the item disappears from the course page, navigation block, and breadcrumbs for that user.
Completion-based rules only fire when completion tracking is enabled at both the course level (Course settings → Completion tracking → Enable completion tracking) and on the specific prerequisite activity (Activity settings → Activity completion → Completion tracking). Without both, the condition can never become true and the target stays locked.
Worked Configuration: Unlock a Quiz After an Assignment Is Submitted
This example assumes Moodle 4.x with the Boost theme; menu labels differ slightly in other themes or versions.
- Enable completion tracking for the course. Go to Course settings → Completion tracking and set Enable completion tracking to Yes. Save.
- Set the prerequisite assignment to require completion. Edit the assignment (e.g., \"Research proposal\"). Under Activity completion, choose Show activity as complete when conditions are met and tick Student must submit. Save.
- Add the Restrict access rule to the target quiz. Edit the quiz (e.g., \"Literature review quiz\"). Scroll to Restrict access and click Add restriction → Activity completion.
- Configure the rule. In the dropdown, select the prerequisite assignment (\"Research proposal\"). Choose Must be marked complete. Leave the visibility icon as the eye with a line (greyed-out with message) so students see the quiz and the reason. Save.
- Optional: combine rules. Click Add restriction again to attach a date window or group condition. Use the Restriction set button to nest All/Any logic if you need branching (e.g., \"Group A after date X OR Group B after assignment Y\").
After saving, a student who hasn't submitted the proposal sees the quiz greyed out with the message \"Not available until Research proposal is marked complete.\" Once they submit, the quiz becomes clickable on the next page load—no teacher action required.
Rule Types and Combination Logic
| Rule type | What it checks | Typical use |
|---|---|---|
| Activity completion | Whether the user has met the completion criteria of another activity in the same course | Sequencing: quiz after assignment, forum after reading a page |
| Grade | A score or percentage on a graded item (assignment, quiz, manual grade item) | Remediation: extra practice if score < 60% |
| Date | Current date/time relative to a start/end window | Scheduled release: open module on Monday, close Friday |
| Group / Grouping | Membership in a specific group or grouping | Differentiated tracks: Group A sees Case Study 1, Group B sees Case Study 2 |
| User profile field | Value of a standard or custom profile field (e.g., department, language) | Role-specific resources: show \"Faculty guide\" only if profile field Role = Teacher |
| Restriction set (nested) | Groups of rules evaluated with All/Any logic | Complex branching: (Group A AND date) OR (Group B AND grade) |
| Manual (teacher toggle) | A checkbox the teacher flips per student | One-off exceptions: grant early access to a specific learner |
When multiple rules sit at the same level, the All/Any toggle at the top of the Restrict access section decides whether every rule must pass (All) or at least one must pass (Any). Nesting Restriction set blocks lets you build expressions like (A AND B) OR (C AND D).
Where the Mechanism Breaks Down
1. Rules that can never become true
If a rule references a grade item the student cannot see, or an activity completion the student cannot reach (because it's in a hidden section or restricted by another rule), the target stays locked forever. Moodle shows no warning to the teacher. Always trace the dependency chain from the student's perspective.
2. Hidden items remain in the gradebook and reports
Restricting access hides the activity from the course page. It does not remove existing grades, completion records, or analytics data. A student who completed the activity before it was restricted still appears in the gradebook and completion reports.
3. Not a security boundary
Users with capabilities like moodle/course:manageactivities or mod/quiz:grade see restricted items regardless of rules. Do not use Restrict access to hide exam answers, salary data, or anything that must stay confidential from other staff. Use separate courses, enrolment keys, or role overrides.
4. Backup/restore fragility
Restriction settings travel with activities through course backup, restore, and import. However, they reference completion and grade items by internal ID. Restoring into a different course, or after deleting the referenced activity, leaves rules pointing at nothing. After a restore, open each restricted activity and verify the rule still points at a valid item.
5. Audit difficulty with deep nesting
More than two levels of Restriction set nesting makes the intended flow hard to read. Document the logic in a separate course page or a shared diagram, and test with a real student account rather than relying on the teacher view (which shows everything).
6. Version and theme differences
Exact labels, rule types, and menu positions change across Moodle releases and themes (Boost, Classic, third-party). Instructions written for Moodle 4.3 may not match 3.11 or a custom theme. Always check the documentation for your exact release before publishing a course.
Verification Checklist
Run these steps in a sandbox course before rolling out to students:
- Enable completion tracking, create a prerequisite activity with required completion, add a Restrict access rule to a second activity pointing at the prerequisite.
- Log in as a test student who has not met the prerequisite. Confirm the target is hidden or greyed out exactly as configured, including the explanatory message.
- Complete the prerequisite as that same test student. Refresh the course page and confirm the target becomes available without manual intervention.
- Log in as a teacher or course editor. Confirm you can still see the restricted item—this proves restrictions are not a security boundary.
- Back up the course and restore it into a fresh shell. Open each restricted activity and verify the rules survive and still reference the intended activities.
Practical Limits to Keep in Mind
- Restrict access evaluates at page load. If a student meets a condition (e.g., submits an assignment) but doesn't refresh or navigate away, the restricted item won't appear until the next request.
- Grade-based rules use the current gradebook value. If a teacher overrides a grade later, the restriction re-evaluates on the next page view.
- Group/grouping rules respect the user's active group mode. In \"Separate groups\" mode, a student only sees activities restricted to their own group.
- Profile field rules match exact string values. A field containing \"Science, Biology\" will not match a rule looking for \"Biology\".
Summary
Restrict access is a flexible, per-activity gating mechanism built on completion, grades, dates, groups, profile fields, and manual toggles. Combine rules with All/Any logic and choose visibility per rule. Enable completion tracking at both course and activity level for completion rules to work. Remember: it's a pedagogical tool, not an access-control system. Test the full student journey with a real account, verify after any backup/restore, and document complex rule sets so future editors can audit the flow.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.