Step 1: Set up two-factor authentication

Before you can sign in to the Admin of your store, you must have a two-factor authentication solution set up and ready to use. To learn more about the authentication process used by each solution, see Using Two-Factor Authentication. By default, Commerce supports Google Authenticator.

Ask your Commerce system administrator which 2FA solutions are supported for the store. Then, complete the setup of your preferred 2FA solution according to the provider’s instructions.

Step 2: Sign in to the Admin

  1. Enter the Admin URL that was specified during the Commerce installation.

    The default Admin URL looks something like https://www.yourdomain.com/your-custom-admin-domain.

    NOTE
    Although this documentation uses admin as the base URL in most examples, it is recommended that you choose a unique and hard-to-guess custom URL for the Admin of your store.

    You can add a bookmark for the page or save a shortcut on your desktop for easy access.

  2. Enter your Admin Username and Password.

  3. (Optional) If a CAPTCHA is enabled for your store, follow the onscreen instructions to resolve the challenge.

    To learn more, see CAPTCHA and reCAPTCHA.

  4. Click Sign in.

    If it is the first time you have signed in to the Admin from the account, you should receive an email with a link to configuration instructions.

Step 3: Complete the 2FA configuration

The following example shows how to pair your Admin account with Google Authenticator.

  1. When the QR code appears, use one of the following methods to capture the code and pair Google Authenticator with your Admin account.

    Set up Google Authenticator

    • Capture QR Code using a smart phone

      On your smart phone, launch Google Authenticator. Tap the plus sign (+) in the upper-right corner of the app. Then at the bottom of the screen, tap Scan Barcode and take a picture of the QR code.

    • Capture QR Code from browser

      If Google Authenticator is installed as an extension in your browser, click the Authenticator icon in the toolbar and capture the page.

    • Manually enter QR code

      Copy the string of text below the QR code. Launch Google Authenticator with either your smart phone or browser, and click the plus sign (+). Then, choose Manual Entry. Under Account, enter the email address that is associated with your Admin account and paste the QR code string into the Key field.

  2. To sign in to the Admin with two-factor authentication, enter the six-digit code generated by Google Authenticator into the Authenticator code field, and then click Confirm.

    Enter the Authenticator code

Reset your password

Reuse of the last four passwords assigned to the account is not allowed.

  1. Enter the Email Address that is associated with the Admin account.

    Forgotten password

  2. Click Retrieve Password.

    If an account is associated with the email address, an email is sent to reset your password.

    NOTE
    An Admin password must be seven or more characters long and include both letters and numbers. See Configuring Admin Security for information about password options.

Sign out of the Admin

  1. In the upper-right corner, click the Account ( Account ) icon.

  2. Click Sign Out.

    Sign out

The Sign In page displays a message that you are logged out. Sign out of the Admin whenever you leave your computer unattended.

Edit account information

  1. Click the Account ( Account icon ) icon.

  2. Click Account Setting.

    Account Information

  3. Make necessary changes to your account information.

    If you change your login credentials, ensure you store them in a secure location.

  4. Enter your current account password.

  5. Click Save Account.

Allow multiple Admin logins

The Admin provides access to manage the orders, customers, products, shipping, and payments functionalities. The default configuration is set to disallow multiple logins for an Admin user account as a security best practice. However, you can change this setting to allow Admin users to be logged in from multiple devices to accommodate your business workflows.

  1. On the Admin sidebar, go to Stores > Settings > Configuration.

  2. In the left navigation panel, expand Advanced and choose Admin.

  3. Expand Expansion selector the Security section.

  4. For Admin Account Sharing, select Yes.

    Allow Admin account sharing

  5. Click Save Config.