Authentication Security
This tab adds extra identity checks after a password: two-factor codes, location checks, IP checks, country rules, JetPass and passkeys. It applies to clients and staff.
Opening the Screen
In the left menu, click Settings, then Security. Click Authentication in the tab row.
Address: {admin}/settings/security?general=authentication
What Is on the Screen
Fields
Two-Factor Authentication
Location Verification
Asks for extra verification when the visitor's city or country changed since their last sign-in.
IP Verification
Checks whether the visitor is using a proxy, VPN or anonymizer service.
Country Rules
Each card has a mode and a country list. The visitor's country comes from their IP address, and at sign-up the country on the form is checked too.
JetPass
Lets someone sign in with a one-time code emailed to them instead of typing a password. It sits beside the password form on the login page. Clients and staff are switched on separately.
Passkeys
Lets someone sign in with a fingerprint, face scan or device PIN instead of a password. A passkey works only on your domain and cannot be phished. Clients and staff are switched on separately.
Tasks
Requiring Two-Factor Authentication for Clients
- Open Two-Factor Authentication and switch on at least one method card, for example the authenticator app.
- Turn on Force Enable for Clients.
- Click Save Changes.
Restricting Access to Certain Countries
- Open Country Rules and set the Access Restriction mode to Allow Only the Selected Countries.
- Pick the countries you serve in the Countries list that appears.
- Click Save Changes.
Visitors from other countries can no longer open an account, sign in or place an order.
Signing In as Staff Without a Password
- Open Passkeys, turn on Enable for Staff and click Save Changes.
- Open your own Account Settings from the profile menu, go to the Security tab and expand Passkeys.
- Click Add Passkey and finish the prompt your device shows.
The key is listed with the date it was added. From the next visit the staff login screen offers Sign In with a Passkey; it opens the panel without a password and without a code.
Things to Watch
The rule is checked at every sign-in, not only at sign-up. A client travelling outside your list cannot sign in or pay an invoice until they are back. Staff logins are exempt.
Every sub-tab has its own Save Changes button. Switching to another sub-tab without saving loses your changes there.
It looks for proxy and VPN usage. To restrict the admin panel to specific IP addresses, use Admin Area IP Restriction on the Settings tab instead.
A password reset, switching two-factor authentication on or off, or the client ending all sessions deletes that account's trusted devices. Clients can also remove single devices from the Trusted Devices list on the Security tab of their account settings.
JetPass delivers its code by email only. Without an active mail module the option still appears, but no code arrives.
Browsers refuse to create or use a passkey on a non-secure address. If your installation address does not start with https, the tab warns you and the feature cannot be used.
Required Privileges
Viewing and saving any sub-tab on this screen needs the SECURITY_SETTINGS privilege.
Related Articles
Merci pour votre retour !
Notre équipe d'assistance est disponible 24h/24 pour tout ce que vous ne trouvez pas ci-dessus.