New discounts and limited-time offers every two weeks! 💸 Don't miss out on your opportunity. SHOP NOW

Two-Factor Authentication for Magento 2

Add extra security level to boost data protection for your e-business. Prevent your store from the common Internet threats like keyloggers, data sniffing and unsecured wi-fi connections. Stay convinced that your Magento account is available only to your staff members.

  • Secure two-step authentication
  • Guaranteed protection against spyware
  • Possibility to include particular IP's in the white list
  • Authentication settings for each user role
  • Your device is the key to your account
$129
60 days money back
Free lifetime updates
90 days free support

👉 As the Internet becomes more rapid and intuitive, users are getting less cautious. They often forget about the essential precautionary measures, when they login to their business accounts. As the saying goes: forewarned is forearmed. When you are prepared, you save yourself from many troubles and mess. The two-factor authentication extension is an easy way to get more confidence about security and double protection of your Magento admin panel.

See how Two-Factor Authentification works

Magento 2 two factor authentification: secure login

Double your Admin panel security

Two-step authentication is a simple yet efficient way to enhance your protection. This presupposes that to access your account, you have to prove yourself in two different ways. Besides from usual login and password, your mobile device becomes a necessary component of your authentication.

Protect your business account against fraud

As more services require to log in, users become less attentive. One-factor verification may become an easy target for the key loggers and data sniffing. The 2-factor authentication extension offers you a trustworthy 2-level solution of the present-day verification method, used by key figures of the industry (e.g. Facebook, Google, etc).

Use Google Authenticator to generate additional security code

Google Authenticator app is a simple way to make your personal device a crucial element for accessing the Magento account. The app generates security codes every 30 seconds, so even if your login and password were hacked somehow, there is one more additional security OTP for login.

Include reliable IP addresses in the white list

To free some IP addresses (e.g. your company) from a double checkup, simply add these IP addresses to the white list in the backend settings.

Enable security code for particular admin roles individually

The Magento 2 Two-factor Authentication extension offers a possibility to configure each admin role individually. Enable additional code for each particular company person.

two-factor-authentication-for-magento-2-flow

2FA extension: mobile verification

two-factor-authentication-for-magento-2-smart

NOTE! The extension is compatible with iPhone (iOS 3.1+), iPad, iPod touch, Android (1.5+) and BlackBerry (OS 4.5-6.0) smartphone.

Check if your device is able to run the Google Authenticator application before using the extension. This Google application generates additional security codes.

Improve your Magento management experience

🔥 Log all admin actions in your web store

To get more from admin management, check our extension Admin Actions Log for Magento 2. Track all the actions by store administrators in a real-time mode. Easily monitor the log history and all the login attempts.

🔥 Allow the admins of the store to work only with particular categories and products

For more flexible work with user permissions, check out the Advanced Permission for Magento 2 extension. You can assign different role permissions for particular managers.

Magento 2 factor authentification

2-step verification is an extra layer of protection based on Google Authenticator or mobile device binding. The single-use 30-second code is apt to protect Magento 2 backend against cybercriminals. Powered by TOTP / HOTP algos, our 2FA plugin doubles your business data resistance against attacks.

🚀 Why Do You Need 2FA?

2FA is a new outline of your security measures that phasing out used-to-be protection measures largely due to the obvious pros:

  • an extra layer of user credentials/account protection;
  • decreased risks of unauthorized access/system breaches;
  • a wide variety of 2FA methods that suit the most discerning users: secret questions, pin codes sent to mobiles, pictures confirmations, more;
  • secure access to confidential business information.

As a result, by avoiding security issues you increase user satisfaction and loyalty to your brand.



To date, more than 90% of Gmail accounts don't use 2FA. This is largely due to Google democratic approach, you can’t simply force users unconditionally accept the two-step authentication. However, in 2018 we see people suffer from banal email hacking and e-commerce fraud.

What makes you think then that the problem won’t affect your business? Let’s take a guess, you may think you are only beginning to be an e-business, you may personally know all the employees, besides you have a small staff, who are easy to control. All these arguments don’t hold much water once your Admin account is hacked.

🚀 What is a Magento 2 authentication factor?

The factor is a credential that is used to verify an access legitimacy. They distinguish the next 2FA types:

    • knowledge (it’s based on a user's knowledge of something): This one is the most common method of authentication. They can be secret questions/characters/words/sentences/numeric combinations/etc.;
    • possession (it’s based on a user's possession of something): The method implies a secret key that is possessed by only one user. One of the most in-use examples is a security token (disconnected/connected/software/etc.);
    • inherence (it’s based on a user's biometric characteristics): They are user's fingerprints, face, voice, iris recognition, typing dynamic and others. The factor is justly considered as one of the safest.

    Our Magento 2 factor authentication uses 30-second Google Authenticator code sent to your mobile device.

    Magento 2 Step Authentication: Pros and Cons

    • double business account protection;
    • increase of your Admin Panel security;
    • additional 30-second-life security password;
    • white lists to free reliable IPs from Magento 2 2FA;
    • extra verification code for an individual admin role;
    • smartphone compatible.
    • the need for sharing your mobile phone number;
    • a possibility of SMS-based authentication distant circumvention;
    • it's never 100%.

    What is two-factor authentification in Magento 2?

    Magento 2 Two-Factor Authentication enhances security by requiring two-step authentication to access the Magento admin panel from all devices. This feature can be implemented using Google Authenticator, Authy, Duo, and other applications. With their help, you get an authentication code that helps prevent illegal attempts to log into your Admin account.

    Adobe partner logo
    Magento Marketplace logo
    4.3
    See 202+ verified reviews
    1 Single points of sales
    Trusted by Customers
    Are Amasty extensions compatible with all themes and extensions by other vendors?
    Amasty extensions work with all plugins we issued and with most 3rd-party plugins. If you come across a compatibility issue with any third-party module, we’ll definitely try to help you. If you face any technical issues, please create a ticket...
    Will I get free support and updates?
    Yes, once you buy any extension(s) by Amasty, you’ll get free lifetime updates for the product(s).Also, you will get 3 months of a free trial for support subscription. Magento support subscription plans:Monthly Annual -20% Lite.vyobs1l-s{text-align:...
    Do you have the installation service?
    Yes, we provide a professional installation service. You can purchase it when ordering an extension. If you buy more than 1 extension in one order, we can install all of them! If you need to configure plugins according to your business needs, you can...
    Can I request a free trial?
    Amasty doesn’t provide any trials of Magento extensions. But we have three months of free support and a 60-day money-back guarantee. There's one exception: Amasty extensions are provided for testing or demo purposes to our official Platinum Partners...
    Can I test an Amasty extension on a staging site before transferring it to a live one?
    Yes, you can install any Amasty extension on a test site and configure all the settings there before doing it on your live store.
    How can I get a refund?
    Amasty provides a 60-day money-back guarantee. In case the acquired extension didn’t meet your expectations, our support team is always ready to help you.  To get a full or partial refund of your order, please create a ticket in our support...
    How can I receive a discount?
    According to the rules of Amasty's Reward Program, you get $15 back to your reward points for every $100 spent. You can spend them to buy other extensions or services from our catalog. These Points are valid for 60 days from the purchase date. You ...
    How to update a Magento 2 Amasty extension?
    To update a Magento 2 extension by manual upload: 1. log in to the customer account; 2. navigate to the Products tab, scroll to thePackages section, andclick the Download link next to the extension that should be updated; 3. Important: If some extension...
    If I need additional features to be added to an Amasty extension, how can I ask for it?
    To leave your feature request, log in to your customer account and open the Products tab. Then, scroll down to the bottom of the page, and leave your feature request in the following form: As soon as you send your request, it is considered by our ...
    Magento 2 Amasty extensions installation
    Each Amasty extension package is provided with the extension files, installation & setup guides, and a license agreement. Some extensions include import files examples as well. So how to install our Magento extension? What is the plugin...
    How can I prolong support?
    When you get any support subscription plan, it will be prolonged automatically. Also, you can cancel your subscription at any time. For this, go to your customer account and open the Subscriptions tab.
    What should I do if my Reward Points have expired?
    According to our reward program, the Reward Points are valid for 60 days starting from the moment they’re transferred to your account. But we always try to stay supportive, so you can create a ticket, and we’ll consider your case individually...
    How can I use my Reward Points?
    How to check your reward points balance? Step 1. Log in to your customer account or create a new one. After this, you will be redirected to your account dashboard. Step 2. In the left menu choose Reward points. Step 3. You will see your current reward...
    Can I change the EE extension to CE for free?
    Usually, no, you can’t exchange modules. Please, contact our support managers and they’ll consider your case individually. → Learn more about our special offers
    How can I get a discount to re-purchase plugins?
    Usually, we don’t provide any discounts. But you can contact us, and we’ll consider your case individually. → Learn more about our special offers
    Customer Reviews

    Are you looking to add specific functionality for this extension or want to acquire a reliable development partner altogether? With custom development services by Amasty, you will receive high quality and cost-effective solutions developed by Magento professionals according to industry’s best practices.

    Request a Quote

    Submit this form now and we will get back to you promptly!

    What feature your extension lacks?

    You can always download the recent version free of charge from your account installing an upgrade is easy

    See Magento (and other software) versions we support and guarantee their compatibility with our extensions

    Version 1.1.6
    Last Update: Nov 18, 2020
    1.1.6 - Nov 18, 2020
    • Improvement code was refactored according to Magento Marketplace standards
    1.1.5 - Feb 05, 2019
    • Fix the issue with saving Two-Factor Authentication data in the user (admin) account if the current user (admin) is whitelisted by IP was resolved
    1.1.4 - Jan 24, 2019
    • Improvement minor visual improvement for the extension settings in the admin panel
    1.1.3 - May 14, 2018
    • Improvement the Google API Key check was added
    • Improvement a small update to the information panes was implemented
    1.1.2 - Mar 29, 2018
    • New added the option to edit the discrepancy for generated verification codes
    • Improved the current IP check for the whitelist functionality
    • Minor code improvements
    1.1.1 - Nov 23, 2017
    • Fixed issue with missing menu tab
    1.1.0 - Aug 28, 2017
    • Compatibility with IPv6 introduced

    Ratings & Reviews

    5
    Rating:
    100% of 100
    © 2009-2021 Amasty. All Rights Reserved.