Two-factor protects administrator sign-in, which is the account that can issue refunds, read every customer record and change payment settings. It is the highest-value control in the product and takes ten minutes.
The failure mode is not a security breach, it is being locked out of your own billing system on a Sunday. Decide now how an administrator who loses their phone gets back in.
Enable it
- Open Settings → Two-Factor Authentication.
- Enable the mechanism you want. A time-based authenticator app is the usual choice and needs no external service.
- Decide whether it is required for all administrators or optional. Required is right; optional means the account that matters most is the one that skipped it.
- Save.
Enroll your own account first
- Open your own administrator profile and start two-factor setup.
- Scan the code with an authenticator app.
- Enter the generated code to confirm the pairing.
- Save the backup codes somewhere that is not the phone you just paired. A password manager or a safe, not a note on the same device.
- Sign out completely and sign back in, to prove it works before anyone else depends on it.
Enroll the team
- Tell people it is coming and what app to install, before you make it required.
- Enroll a second full administrator and confirm they can sign in independently.
- Only then make it required for everyone.
One super-administrator with two-factor and no recovery path is a single point of failure for the whole business.
When somebody is locked out
- They use a backup code, if they kept them.
- Otherwise another full administrator disables two-factor on their account, they sign in, and they re-enroll immediately.
- If nobody can sign in at all, recovery is a database-level operation, which means downtime and a support conversation. This is the situation the second administrator exists to prevent.
What it does not cover
Two-factor protects interactive sign-in. It does not protect API credentials, which authenticate without a person — restrict those by role and by address instead. See Create API credentials. It also does not protect customer accounts in the client area; that is a separate setting.