Using Two-Factor-Authentication

The following instructions show how to configure two-factor authentication during your initial sign in and how to authenticate your identity. For complete instructions, see Admin Sign In.

Google Authenticator

Step 1: Configure Google Authenticator

  1. Enter your account credentials and sign in to the Magento Admin.

    A new authenticator screen appears with a QR code.

  2. Open the Google Authenticator app on your mobile device.

  3. Click the plus sign ( + ) to add a new entry. Then, do the following:

    • Line up the red box with the QR code to scan with the camera on your smart phone.

    • When it recognizes the QR code and adds an entry, enter that 6-digit code in the Admin Authenticator code field.

  4. When complete, click Confirm.

    Google Authenticator QR code Google Authenticator QR code

Step 2: Sign in with Google Authenticator

  1. Enter your account credentials and sign in to the Magento Admin.

    Google Authenticator - signin Google Authenticator

  2. Open Google Authenticator on your mobile device.

  3. When prompted, enter the six-digit Authentication code.

  4. To save the authentication for future logins, select the Trust this device, do not ask again checkbox.

  5. When complete, click Confirm.

Duo Security

Duo offers a free trial, and charges according to the number of users that are associated with the account. Follow their instructions to set up your account and download the app. Duo Mobile is available through Google Play or iOS App Store.

Step 1: Configure Duo Security

  1. Enter your account credentials and sign in to the Magento Admin.

  2. When the Duo Setup page appears. Click Start setup and do the following:

    Example storefront - Duo setup Duo Setup

    • Select your device.

      Duo authentication - select device Device Type

    • When prompted, enter your phone number, and click Continue.

      This example requests your phone number, because we are using a mobile device.

      Duo authentication - enter phone number Enter Your Phone Number

    • When prompted to install Duo Mobile for your phone type, click I have Duo Mobile.

      Duo authentication - verify app installation Verify App Installation

  3. Open Duo Mobile and scan the QR code to sync the authenticator with Magento. A checkmark appears when the activation is complete.

    Duo authentication - verification code Duo Verification Code

  4. To configure your settings for the device, choose the action that you want to take place when you sign in.

    • Ask me to choose an authenticator method — Allows the user to select when logging in and authenticating in the Magento Admin.
    • Automatically send this device a Duo Push — Sends a message to your device to accept or deny for access.
    • Automatically call this device — Calls and provides a passcode for entering

    Duo verification actions Duo verification code

Step 2: Sign in with Duo Security

The following example shows the options for Ask me to choose an authenticator method:

  1. When prompted, enter your Magento Admin credentials to sign in.

    Duo - signin Duo access

  2. Choose the method that you want to use to authenticate:

    • Send Me a Push — Click to receive a push notice to Duo Mobile. Accept to authenticate.
    • Call Me — Click this option, receive a call with a code, and enter the passcode.
    • Enter a Passcode — Click this option to receive and enter a passcode.
  3. Complete the push or code to fully sign in to the Admin.

Authy

Authy offers their app and service at no charge to users. Follow their instructions to download and set up the app for your device or browser. To learn more, see the Authy documentation.

Step 1: Configure Authy

  1. Enter your account credentials and sign in to the Magento Admin.

    Authy registration Authy registration

  2. When prompted to register yourself with Authy, do the following:

    • Select your Country.

    • Enter your Phone number.

    • Select one of the following Verification methods:

      • SMS
      • Call Me
    • Click Continue.

    A message is sent to your phone through SMS text or a call.

  3. Enter the Verification code that you receive and click Verify.

  4. When complete, click Confirm.

    Authy verification code Authy verification code

Step 2: Sign in with Authy

  1. Enter your account credentials and sign in to the Magento Admin.

    Authy - signin Authy access

  2. Choose one of the following methods to authenticate:

    • Use one touch — Sends an alert to your Authy app. In the app, accept the access.
    • Use authy token — Prompts to enter a code from your Authy app.
  3. If you have trouble signing in, choose the method you want to use to receive the code. Then, enter the code that you receive to access the Admin.

    The app includes these additional emergency methods.

    • Send me a code via SMS — A text SMS message is sent to the configured mobile device.
    • Send me a code via phone call — The user receives a phone call with a code.

    Your account is verified and opens.

U2F (Yubikey and others)

Follow the instructions from the solution provider to configure your U2F device. For more information, see the vendor documentation, such as YubiKey by Yubico.

  1. Enter Magento Admin account credentials and sign in to your account.

    U2F key access U2F Key Access

  2. Press the button on the key.

    Authentication immediately triggers and opens the Admin.

  3. Insert the U2F key into a USB port on your computer.