Multi-factor authentication (MFA) adds an extra layer of protection to your website login. In addition to your username and password, you’ll enter a temporary six-digit code from an authenticator app on your phone or another device.

This means that if someone obtains your password, they still cannot log into your account without the additional verification code.

Each person with access should have their own website login. If your organization currently shares an account, contact interGen support before setting up MFA.

Before You Start

You’ll need an authenticator app that can generate verification codes.

Common options include:

  • Google Authenticator

  • Microsoft Authenticator

  • Authy

  • A password manager that supports verification codes

If you already use one of these for another account, you can use the same app for your website.

Set Up MFA

1. Log into your website

Go to your website’s administrator login:  https://yourwebsite.com/administrator

Log in with your usual username and password.

2. Open your account settings

user edit accountIn the upper-right corner of the Joomla administrator area:

  1. Select the User Menu.

  2. Select Edit Account.

  3. Open the Multi-factor Authentication tab.

MFA can only be set up by the person who owns the account. Another administrator cannot configure it on your behalf.

user mfa tab3. Add a verification code

Under Multi-factor Authentication, select the option to add a Verification Code.

Joomla will display a QR code on the screen.

4. Add the website to your authenticator app

Open your authenticator app and choose the option to add a new account.

user mfa qr code

Use your phone or device to scan the QR code displayed by Joomla.

Your authenticator app will begin displaying a six-digit code for your website.

5. Confirm the setup

Enter the current six-digit code from your authenticator app into Joomla when prompted.

Complete the setup and save your changes.

MFA is now enabled for your account.

What Changes When You Log In?

You will still enter your Joomla username and password as usual.

After that, Joomla will ask for your verification code. Open your authenticator app, find the entry for your website, and enter the current six-digit code.

These codes change automatically, so you do not need to remember or save them.

Save Your Backup Codes

After setting up MFA, Joomla can provide backup codes.

Save these somewhere secure and separate from your authenticator device. Each backup code can be used once if you cannot access your normal verification method.

Do not store your backup codes in the same place as your website password.

Getting a New Phone?

Before removing or resetting your old phone, make sure your authenticator information has been transferred to your new device or add another authentication method to your Joomla account.

If you lose access to your authenticator without another MFA method or backup code available, you may be unable to log into your website.

Need Help?

If you have trouble setting up MFA or are unsure whether it is working correctly, contact interGen support at This email address is being protected from spambots. You need JavaScript enabled to view it. or open a support ticket.

Please do not send passwords, verification codes, QR codes, or backup codes by email.