Protecting Against Unauthorized Backend Access

The security of your administration area is the heart of your shop's protection. Magento 2 offers in-depth options to regulate access.

Key Security Parameters

Under Stores > Configuration > Advanced > Admin > Security, you will find the following options:

  • Admin Session Lifetime: Define after how many seconds of inactivity an admin is automatically logged out (recommended: 3600 sec.).
  • Password Lifetime: Force administrators to change their password every 90 days.
  • Login Password Error Threshold: Set the number of failed attempts after which an admin account is temporarily locked.
Pro Tip: Always use the "Add Secret Key to URLs" option to prevent CSRF (Cross-Site Request Forgery) attacks. This setting is enabled by default and should not be disabled.

Server-Level Security

In addition to Magento's features, we protect your installation with Imunify360 and Web Application Firewalls.

Secure Hosting Now
Was this answer helpful? 0 Users Found This Useful (0 Votes)