Two-step authentication for users
You can add extra security to your store by requiring staff members to use two-step authentication when they log in. If you don't require two-step authentication, users can still set up two-step authentication on their own in their Shopify accounts. Requiring two-step authentication can protect your store from unauthorized access, even if passwords are compromised.
You can set either of the following options:
- Secure sign-in method is required: This setting requires the user to use a secure sign-in method to log in.
- Secure sign-in method is not required: This user can choose to use a secure sign-in method.
This setting applies to each user individually, and doesn't depend on the role that's assigned to them.
Only eligible users can access two-step authentication settings.
By default, required two-step authentication is recommended for new users. In this case, users are prompted to set up two-step authentication when they log in. You have the option to deactivate two-step authentication when you add staff.
You can also change two-step authentication so that it isn't required for an existing user. Changing the two-step authentication setting from not required to required logs the user out of Shopify. Before changing a users authentication requirements, verify that they aren't in the middle of a task.
After you remove the two-step authentication requirement for existing users, their authentication settings aren't updated automatically. In this case, the user needs to change the security settings for their own account. Until the user deactivates two-step authentication in their own security settings, they're still prompted to complete the two-step authentication setup for any store where they have a user account, whether or not the store is in your organization.
On this page
Change two-step authentication settings
From your Shopify admin, go to Settings > Users.
Click the user that you want to change the security settings for.
In the Secure sign-in method section, select whether a secure sign-in method is required or not when the user logs in through a browser.
Click Save.
Staff member two-step authentication and Shopify ID
Two-step authentication is tied to a staff member's individual Shopify ID, not to your store. From your Shopify admin, you can require or not require two-step authentication for a staff member, but you can't view or change the phone number, authentication app, or recovery codes that they've set up for their Shopify ID. Each staff member manages their own authentication methods from their account security settings.
Removing a staff member and re-inviting them by using the same email address doesn't reset or remove two-step authentication on their Shopify ID. The staff member keeps the same Shopify ID, so they continue to log in by using their existing two-step authentication method.
If a staff member loses access to their two-step authentication method, then they need to complete the account recovery process for their own Shopify ID. Refer to troubleshooting login for the recovery steps.
If your store or organization is on the Shopify Plus plan and you've verified ownership of your domain, then you can reset two-step authentication for eligible staff members from the Shopify admin without requiring them to use the account recovery flow. Two-step authentication can be reset only for staff members whose email address uses a domain that you've verified.