Securantis

PrestaShop

Enable and use 2FA for the PrestaShop back office (TOTP and email codes) — activation, recovery and troubleshooting

Complete guide to enable 2FA in the PrestaShop back office: TOTP and email code options, saving recovery codes and recovery procedures in case of lockout.

← Back to help center

Securantis how-to guide

Purpose of this article

This guide explains how to enable and configure two‑factor authentication (2FA) for access to the PrestaShop back office using the Securantis module, using TOTP codes (authentication apps) and/or email‑sent codes depending on availability. You will also find best practices for saving recovery codes, security advice and troubleshooting procedures in case of lockout.

Who this article is for

  • PrestaShop (1.7 to 9) store administrators who want to protect back‑office access.
  • Support teams and security officers who must define a recovery procedure.

Prerequisites

  • Securantis module installed and enabled in PrestaShop. Some features require protection to be first enabled on at least one administrator account.
  • Administrator access to the back office (existing account with sufficient rights).
  • For the email option: working email sending configuration from PrestaShop (SMTP or native sending) and an accessible inbox.
  • For the TOTP option: smartphone or device with a TOTP‑compatible authentication app (e.g. Google Authenticator, Authy, Microsoft Authenticator) and a synchronized system clock.

Activation and configuration steps (recommended order)

  1. Enable the 2FA module
  • In the back office, open the Securantis module management page and enable the global 2FA module if this option is present. Note that some features may require the Securantis license to be activated.
  • Expected result: the 2FA module is active and ready to protect accounts.
  1. Enable 2FA for your administrator account
  • In your administrator profile, choose to enable 2FA for your account. Follow the wizard provided by the module.
  • Expected result: the activation flow starts and you are prompted to choose a method (TOTP if available, otherwise email).
  1. Configure TOTP (recommended method)
  • If the module offers TOTP: start the configuration, display the QR code and scan it with your authentication app.
  • Enter the TOTP code generated to verify the association.
  • Immediately download or copy the recovery codes displayed and store them in a password manager or a secure offline location.
  • Expected result: your app generates valid 6‑digit codes and TOTP 2FA is linked to your account.
  1. Enable sending codes by email (fallback or alternative)
  • If you cannot use TOTP, enable the email code sending option offered by the module.
  • Verify that the administrator account email address is correct and test sending a code.
  • Expected result: you receive a unique code by email usable for authentication.
  1. Manage and secure the recovery codes
  • Print or save the recovery codes provided during TOTP activation. Each code is generally usable only once.
  • Store these codes in a password manager or on a secure medium (encrypted USB key, offsite paper safe).
  • Expected result: you have a way to recover access if the TOTP device is lost.

Prudent settings and recommendations

  • Enable 2FA first on an administrator account you control. Avoid enabling global 2FA for all admins simultaneously without a tested recovery procedure.
  • Keep recovery codes in at least two secure and separate locations (e.g. password manager + paper copy stored offsite).
  • For organizations: implement a documented internal procedure for recovering a locked 2FA account (e.g. secondary administrator or HR‑validated process).
  • Never share recovery codes, passwords or the TOTP key by unsecured email or chat.

Common errors and likely causes

  • No reception of email codes: incorrect SMTP configuration, emails flagged as spam, server sending limits, or incorrect account email address.
  • Invalid TOTP codes: device (smartphone) clock not synchronized, authentication app misconfigured (wrong secret) or entering the code too late before expiry.
  • Lockout after global 2FA activation: absence of recovery codes and no other administrator with 2FA access or reset procedure.

Troubleshooting procedures

  1. I do not receive codes by email
  • Check the spam/junk folder.
  • Send a test email from PrestaShop (or the email configuration page) and check email logs if available.
  • Verify SMTP configuration and hosting server sending quotas.
  • If the server blocks sending (hosting policy, blacklist), configure a third‑party SMTP service or correct the configuration.
  1. TOTP codes do not work
  • Synchronize the smartphone time (enable “network time” setting) or use the authentication app’s time sync feature if available.
  • Reassociate TOTP: if possible, reset the TOTP configuration from your profile and scan the QR code again.
  • If you still have recovery codes, use them to access and reconfigure 2FA.
  1. I am completely locked out (no access, no codes)
  • Log in with another administrator account that still has access if you have one and revoke or reset 2FA for the locked account.
  • If no other admin is available and you need Securantis intervention: contact support. Important note: for any intervention requiring administrator access, Securantis accepts access only via the secure client area and only after validation of the terms of service and payment, following the paid intervention procedure.

Security precautions

  • Never disclose your passwords, TOTP keys or recovery codes by email or chat.
  • Protect access to the admin email inbox: if the email is compromised, email‑sent codes are worthless.
  • Maintain a clear, tested recovery procedure (secondary admin account, encrypted storage of recovery codes, designated responsible person).

When to contact Securantis support

Contact support if:

  • The Securantis module will not install or generates unexpected technical errors.
  • You cannot send emails despite correct SMTP configuration and no server‑side errors.
  • You are locked out with no recovery means and need an administrative reset. In this case, note that Securantis follows a strict procedure: any intervention requiring access to your back office goes through the secure client area and is performed only after acceptance of the terms and payment if the intervention is billable.

What support will not do

  • Support will never ask for your passwords by email or chat.
  • Securantis will not automatically remove malware: any quarantine, removal or restoration will be performed only after human analysis and validation.

Summary and quick best practices

  • Enable 2FA on one administrator account at a time and test the recovery procedure.
  • Prefer TOTP (authentication app) and keep recovery codes offline.
  • Configure email as a fallback only if the email inbox is highly secured.
  • Document the internal recovery procedure and perform periodic tests.

If you need further assistance, describe precisely: the PrestaShop version, the Securantis module version, the 2FA method configured (TOTP or email), and any visible error messages. This will speed up diagnosis by the support team.

Cookies

We use cookies necessary for the operation of the site. With your consent, we can also use analytics and personalization cookies. Learn more.

Necessary

Essential for the site and the client area.

Active