Two-Factor Authentication for Magento 2


Magento 2 Two-Factor Authentication extension is the effective solution with the latest advancement to help e-commerce business increase system security and be better protected from unauthorized access.


60-day Money Back

Frequent Update

365-day Support

Magento 2 Two-Factor Authentication for Magento 2.2.x, 2.3.x, 2.4.x

Adobe Commerce
2.2.x, 2.3.x, 2.4.x

Live Demo


You've just added this product to the cart:

Two-Factor Authentication

Two-Factor Authentication for Magento 2

You've just added this product to the cart:

Two-Factor Authentication Pro

Two-Factor Authentication for Magento 2

From February 1, 2022, we are launching Product Subscriptions
Buy now to get 15% cashback and other appealing incentives.
Learn more →


Problems - Solutions & Applications

It has become easy to steal users credentials using key loggers, phishing attacks, viruses etc. Many stores are attacked due to the the low security of admin accounts.

In some cases, store owners would like to set specific access right to different admins: less or more authentication.

While in Magento 2 default, the process to sign in admin account is quite simple using username and password. Therefore, the account information is likely to be vulnerable to malicious stealing activities.

An extra layer using authentication code is required when there is any login attempt to admin panel. This second factor strengthens the defense wall of admin accounts and keep safe for store confidential data

Employees taking up admin roles can use personal mobiles to verify access easily while keep ensuring security for their stores as well as sensitive business data.
As a result, administration job becomes more professional and secured.

Store owners can save security cost on using any assistance software or resetting password thanks to the support of two authentication factor. This is the great beneficial feature of 2FA.

Two-Factor authentication to access admin account

Forcing to use Two-factor authentication Magento 2 Two-Factor Authentication (2FA) requires admin users to pass two verification steps to access store data. The first step is simple with the password and username and the second step is much more secured with unique authentication code. Any steps fails to pass, the admin users will fail to access. As a result, the store data is protected safely.

Support from mobile authentication apps Mobile authentication app integration is well supported in this extension. The apps such as Authy, Google Authentication will create a confirmation code to help admins account to register 2FA after scanning QR or using manual key. After successfully registering, a unique code which will be provided by the apps for 2FA verification every time an admin logs in.

No requirement if being trusted

Activate trusted device function, set trusted time One of the most noticeable feature of this extension is setting trusted device function. In case the admin would like to avoid the verification being repeated every time signing in, it is easy to set the account as the trusted device within a specific time period (e.g.,30 days, 60 days).

Quick login without authentication code in the next login It is very easy to enable trusted device and set the trusted time by days from the extension configuration section. Then after the first time confirming the account successfully, as long as within the trusted time, the second verification is not required for the next login times. With this feature, it is time-saving for key store admins whose accounts are believed to be reliable.

Trusted device list

It is easy to manage all trusted verified admin roles by the Trusted Device list. The information of logged users are recorded clearly with the following details:

  • Device Name
  • IP address
  • Address
  • Last login time

Besides, super admin or store owners can easily remove any admin accounts from the trusted device in case there is any account updates. Therefore, admin panel can be protected well from the ill-intentioned access.

AVADA Marketing Automation by Mageplaza (recommended)

magento 2 avada email marketing

All-in-one platform for email marketing that allows you to:

  • Follow up and convert customers by Automation Campaigns: Welcome series, Abandoned Cart emails, Order follow up, Cross-sell, Upsell emails
  • Promote your brand and quickly drive sales by sending mass Newsletter Emails
  • Send your messages to the right people and increase conversions with Advanced Segmentation
  • Collect leads and deliver promotions with stunning Signup Forms, and Spin to Win

Two-Factor Authentication's more features

Force Using 2FA

Enable/ Disable requiring users to register 2FA.

Trusted Time

Set trusted time by days.

Reset by command line

Able to reset two factor authentication for an admin by using command line

Mobile friendly

Be well responsive with mobiles, desktop, tablets, and other screen sizes.

Full Features List

Admin account setting 2FA

  • Setting account information: User name, Email, password
  • Enable/ Disable 2FA for the account
  • Input confirmation code from authentication app
  • Use a unique authentication code for each time login
  • Click on trust this device when login to save second authentication confirmation for a specific days
  • View Trusted Device list
  • Remove an admin account from the Trusted Device list

General configuration


Kindly follow this guide. Firstly, turn off Forcing to use 2FA function. Then the admin accounts which is not set as trusted device and turn on 2FA will have to use 2FA.

Yes, you can easily see from admin backend and click on remove button to do any removing accounts.

There are two steps. The first is simple with username and password, the second is authentication code provided by the mobile authentication app

We recommend you use Authy and Google Authentication for the best result.

You can do by enabling the trusted device function and set the trusted time by days. Then, in the first login, click on Trust this device for x days. It can be done properly.


Can't find your feature?

Are you looking for a feature in Two-Factor Authentication. Tell Elle your wants and needs.

Chat with Elle

Are you an agency?

Do you often visit us for purchasing extensions and technical support? Speak to April to learn about your exclusive benefits on Mageplaza

Chat with April


03 February 2021


This helps us to set admins and trusted devices quickly so that we don't have to worry about security issues. It's a must-have for stores with many admins. Easy to configure as well.

Jim Burton -Verified Purchase
28 January 2021

First-time customer

I wanted to find a more secure way to protect my site. Luckily to find this. The design was beautiful and surprisingly it's free. I'm looking forward to using your other extensions.

Emily Howard -Verified Purchase
12 September 2019

Perfect as always

I want to say the extension is beautiful from the design, security function, but support is the most impressive. They offer their great help when I need it. Wish that I could purchase all my extensions from Mageplaza. It is surely beyond FIVE STAR support compared to other vendors in the Magento market.

Kathryn -Verified Purchase

Leave a Review

How do you rate this product?

Your email address on Mageplaza's store

Plain text, no HTML tags.