Authentication Security
This tab adds extra identity checks after a password: two-factor codes, location checks, IP checks, country rules, JetPass and passkeys. It applies to clients and staff.
Opening the Screen
In the left menu, click Settings, then Security. Click Authentication in the tab row.
Address: {admin}/settings/security?general=authentication
What Is on the Screen
Fields
Two-Factor Authentication
Location Verification
Asks for extra verification when the visitor's city or country changed since their last sign-in.
IP Verification
Checks whether the visitor is using a proxy, VPN or anonymizer service.
Country Rules
Each card has a mode and a country list. The visitor's country comes from their IP address, and at sign-up the country on the form is checked too.
JetPass
Lets someone sign in with a one-time code emailed to them instead of typing a password. It sits beside the password form on the login page. Clients and staff are switched on separately.
Passkeys
Lets someone sign in with a fingerprint, face scan or device PIN instead of a password. A passkey works only on your domain and cannot be phished. Clients and staff are switched on separately.
Tasks
Requiring Two-Factor Authentication for Clients
- Open Two-Factor Authentication and switch on at least one method card, for example the authenticator app.
- Turn on Force Enable for Clients.
- Click Save Changes.
Asking for an SMS Code on Every Sign-In
- On the Two-Factor Authentication tab, switch on the SMS Verification card. If SMS is the only method you want, switch off TOTP and Email Verification.
- Turn on Force Enable for Clients and leave Trusted Device Duration (Clients) at 0.
- Click Save Changes.
The client enables SMS verification at the next sign-in. From then on, every sign-in asks for the code sent to their phone.
Restricting Access to Certain Countries
- Open Country Rules and set the Access Restriction mode to Allow Only the Selected Countries.
- Pick the countries you serve in the Countries list that appears.
- Click Save Changes.
Visitors from other countries can no longer open an account, sign in or place an order.
Signing In as Staff Without a Password
- Open Passkeys, turn on Enable for Staff and click Save Changes.
- Open your own Account Settings from the profile menu, go to the Security tab and expand Passkeys.
- Click Add Passkey and finish the prompt your device shows.
The key is listed with the date it was added. From the next visit the staff login screen offers Sign In with a Passkey; it opens the panel without a password and without a code.
Things to Watch
An account with two-factor verification is asked for a code on every sign-in, whether or not its IP address changed. The only exception is Trusted Device Duration. When it is above 0 and the user ticked "trust this device", that browser skips the code until the period ends.
The rule is checked at every sign-in, not only at sign-up. A client travelling outside your list cannot sign in or pay an invoice until they are back. Staff logins are exempt.
Every sub-tab has its own Save Changes button. Switching to another sub-tab without saving loses your changes there.
It looks for proxy and VPN usage. To restrict the admin panel to specific IP addresses, use Admin Area IP Restriction on the Settings tab instead.
A password reset, switching two-factor authentication on or off, or the client ending all sessions deletes that account's trusted devices. Clients can also remove single devices from the Trusted Devices list on the Security tab of their account settings.
The SMS method sends its code by SMS only; the email method and JetPass send theirs by email only. The client switches of the Two-Factor Authentication notification template do not change this. The code reaches the account holder alone, never a contact or a sub-account.
The SMS step shows the last four digits of the phone number on file. If the code cannot be sent, the client reads a message in their own language asking them to contact support. At staff sign-in, the message points to the SMS or email module settings instead.
JetPass delivers its code by email only. Without an active mail module the option still appears, but no code arrives.
Some imported accounts have no password. JetPass, sign-in links from an integration and social sign-in then show a message instead. The client sets a password with Forgot Password?, then every method works.
Browsers refuse to create or use a passkey on a non-secure address. If your installation address does not start with https, the tab warns you and the feature cannot be used.
Required Privileges
Viewing and saving any sub-tab on this screen needs the SECURITY_SETTINGS privilege.
Related Articles
Дякуємо за відгук!
Наша служба підтримки на зв’язку цілодобово з усього, чого ви не знайшли вище.