Moduł Two-Factor Authentication (2FA) for Back Office Login dla PrestaShop

Wersja: 1.0.2 (2026-08-26) | Zgodność: PrestaShop 1.6.0.4 - 9.2.0
Protect your back office with two-factor authentication (2FA). Every employee signs in with a one-time TOTP code from Google Authenticator or Authy, so a stolen admin password is no longer enough. Force 2FA across your team.
Wsparcie
  • 1 rok 0,00 €
0,00 € 69,99 € -100%
Netto
Liczba licencji
Accepted payment methods

 

⚡ PrestaShop asks for nothing but a password at the back-office door. This module adds a second one: two-factor authentication (2FA), where every employee follows their password with a 6-digit code taken from their own phone. Setting it up is a single QR scan, and from that moment the door needs something the employee has, not only something they know.


Why choose our module?

  • Give each employee their own key. Every staff account is protected on its own, so your weakest password stops being your biggest risk.
  • Turn it on once for the whole team. Anyone without a key is walked through setup before they can open the back office.
  • Get back in even if a phone is lost. Every employee holds a personal recovery code, and an IP address you add to the exempt list opens the back office again if a whole team is ever stuck.
  • Do not ask for a code at every login. Employees can trust their own browser and skip the code, while every connection, wrong code and lockout is still written to the activity log.
  • Watch who opens your back office. An email can reach you on every successful sign-in and, on its own switch, whenever a code is rejected or an account locks out, so a fraudulent access does not wait until you next open the back office.
  • Stop anyone from guessing codes. Ten wrong codes lock the account, and each code works only once, so an intercepted one is already dead.
  • Stay independent of any external service. Codes are generated on the employee's phone and checked by your own shop. No third party, no subscription, no API key.


What makes this module essential for your store?

  • Stop a stolen password from becoming a stolen store

A back-office password can be phished, guessed or reused from another site that was breached. With 2FA active, an attacker also needs the code sitting on your employee's phone, which they do not have. Your orders, customer data and settings stay protected even if a password leaks.

TOP feature! ⚡


  • Protect every employee, not just the owner

Each staff member gets their own secret key, set up in seconds by scanning a QR code with any authenticator app. Security stops depending on one strong password: every account is covered on its own.

BASIC! ✅


  • Enforce 2FA across your whole team automatically

Turn on Force 2FA and every employee must set up a key before they can open the back office. Staff without a key are walked through a single-screen enrollment the next time they log in.

ESSENTIAL! ✌️


  • Never get locked out of your own store

Every employee holds a personal recovery code that works once, so a lost phone is never a locked door, and an exempt IP address gets you back in from your own office in an emergency. You are always in control.

POWERFUL! ✨

What are the main features of this module?

  • Personal TOTP key per employee

Every employee sets up their own secret by scanning a QR code with Google Authenticator, Authy, Microsoft Authenticator or any RFC 6238 app, or by typing the key in by hand. The 6-digit code refreshes every 30 seconds and is checked on your own server, so the secret never leaves your store.


  • Force 2FA for the whole team

One switch requires every employee to set up a key before they can open the back office. Staff without one are walked through a guided single-screen setup at their next login: they scan the QR code or type the secret by hand, confirm with a 6-digit code, and they are protected.


  • ⚙️ Central 2FA management

A single table lists every employee with their 2FA status, setup date, last verification and failed-attempt count, so you see who is protected at a glance. Revoke any key in one click and it applies at their next login, or reset a lockout counter to unlock somebody instantly.


  • Brute-force lockout and replay protection

Accounts lock automatically after 10 consecutive wrong codes, and recovery-code attempts count towards the same limit. Each code works only once within its 30-second window, so a code that was intercepted is already worthless by the time it is replayed. An administrator can lift a lockout at any time.


  • Single-use recovery code per employee

Each employee gets their own recovery code, hidden on their row until they choose to reveal it, so losing a phone never means losing access. It works exactly once, and a new one is issued from the same table whenever you ask for it. If a whole team is ever locked out, adding an IP address you control to the exempt list gets you back in.


  • ☑️ Trust your own devices

Employees can tick a box to skip the code on a browser they trust, and you decide how often a code is asked again, from every login to once a month. Trusted devices are cleared automatically whenever that employee's password or key changes.


  • IP addresses exempt from 2FA

Exempt up to 32 addresses you control, such as your office or your VPN, and signing in from there never asks for a code. The check runs before every other rule, so even the forced setup is skipped, and it uses the address your server reports because forwarded headers can be faked.


  • ✏️ Activity log of every sign-in

A dedicated tab records every connection, wrong code and lockout, newest first, with the date, the employee, their email and the IP address. Entries are colour-coded so a problem stands out at a glance, and only an employee allowed to edit employees can clear it, so the trail cannot be quietly erased.


  • ✉️ Email alerts on sign-ins and failed attempts

Get an email the moment anyone signs in to your back office, with the employee, the IP address, the city and country the connection came from and the method used. The location is read from the geolocation database PrestaShop already installs, so nothing is sent to any outside service. A separate switch warns you when a code is rejected or an account locks out, which is the signal that somebody is trying to get in, so you can watch for intrusions without a message on every login.

FREQUENTLY ASKED QUESTIONS - FAQ


Which authenticator apps does it work with?

➡️ Any app that follows the TOTP standard (RFC 6238): Google Authenticator, Authy, Microsoft Authenticator, FreeOTP, 1Password, Bitwarden and many more ⚙️.



What happens if an employee loses their phone?

➡️ They sign in with their personal recovery code, then regenerate their key from the management table in one click ✔. And if nobody can get in at all, adding an IP address you control to the exempt list opens the back office from there, so there is always a way back ✅.



Can I require every employee to use 2FA?

➡️ Yes. Turn on Force 2FA for all employees and anyone without a key is guided through setup before they can access the back office ⚡.



Could my whole team ever get locked out?

➡️ No. Beyond each employee recovery code, any address on the exempt IP list skips 2FA entirely, so you always have a way back in from an address you control.



Do employees have to enter a code at every login?

➡️ No. Turn on trusted devices so they can skip the code on a browser they trust, and choose how often a code is asked again, from every login to once a month.



Will I know when someone signs in to the back office?

➡️ Yes. Enable the email alert and you get a message on every new sign-in with the employee, the IP address, the city and country it came from, and the method used.



Does it change how my customers log in?

➡️ No. This module protects the back office (employee) login only. Your storefront and customer accounts are not affected in any way.



Does it need an internet connection or an external service?

➡️ No. Codes are generated on the employee's device and checked on your own server. No third-party service, no subscription and no API key ⚙️.



Does it work with multistore and multiple languages?

➡️ Yes. The module is multistore ready and available in 18 languages, including regional variants.



Do you offer support and updates?

➡️ Yes. You get free updates and support from idnovate. Contact us before and after your purchase for any question.

Wersja
1.0.2 (2026-08-26)
Zgodność
1.6.0.4 - 9.2.0
Ocena
0
Oceny
0
Preuzimanja
1
Języki
EN, AG, BR, CB, DE, ES, FR, GB, IT, MX, NL, PE, PL, PT, QC, RO, RU, VE
Wymaga usługi zewnętrznej
Nie

Klienci którzy zakupili ten produkt kupili również: