Multi-factor authentication (MFA) adds an extra layer of protection to your website login. In addition to your username and password, you confirm it is really you with a six-digit code from an app on your phone, or with your fingerprint or face on a device you have registered.

This means that if someone obtains your password, they still cannot log into your account.

Each person with access should have their own website login. If your organization currently shares an account, contact interGen support before setting up MFA.

In the screenshots below, the red outline shows what to click or fill in next. Numbers show the order when there is more than one step on a screen.

Before You Start

You will need an authenticator app that can generate verification codes. Common options include:

  • Google Authenticator
  • Microsoft Authenticator
  • Authy
  • A password manager that supports verification codes (1Password, Bitwarden, and others)

If you already use one of these for another account, you can use the same app for your website.

Tip: Google Authenticator and Microsoft Authenticator can back up your codes to your Google or Microsoft account. Turn this on in the app so your codes come with you if you replace your phone.

Set Up MFA

1. Log into your website

Go to your website’s administrator login: https://yourwebsite.com/administrator

Enter your username and password, then select Log in.

Joomla administrator login screen with the Username field, Password field and Log in button circled

2. Open your account settings

In the upper-right corner, select User Menu.

Joomla dashboard header with the User Menu button circled

Select Edit Account.

User Menu dropdown with Edit Account circled

Open the Multi-factor Authentication tab.

Edit Profile screen with the Multi-factor Authentication tab circled

MFA can only be set up by the person who owns the account. Another administrator cannot set it up on your behalf.

3. Add a verification code

Under Verification code, select Add a new Verification code.

Multi-factor Authentication tab with the Add a new Verification code button circled

4. Scan the QR code with your authenticator app

Open your authenticator app on your phone and choose the option to add a new account (in Google Authenticator, tap + and then Scan a QR code). Point your phone at the QR code on your screen.

Add a Multi-factor Authentication Method screen with the QR code circled

Your app will start showing a six-digit code for your website. The code changes every 30 seconds.

5. Enter the code and save

Type the current six-digit code from your app into the Enter the six digit verification code box (1), then select Save & Close (2). If the code changes before you finish, just use the new one.

Verification code setup screen with the six digit code field marked 1 and the Save and Close button marked 2

MFA is now enabled for your account.

Save Your Backup Codes

When MFA is turned on, Joomla creates a set of backup codes. Each one can be used once to log in if you cannot use your phone.

On the Multi-factor Authentication tab, select Print these codes.

Multi-factor Authentication tab showing MFA is enabled, with the Print these codes link circled

Print the codes or save them in your password manager.

Backup Codes screen with the list of ten backup codes circled

Store your backup codes somewhere secure and separate from your phone. Do not store them in the same place as your website password.

Optional: Add a Passkey (Fingerprint or Face)

If your computer or phone has a fingerprint reader or face recognition (for example Touch ID on a Mac, or Windows Hello), you can register it as a second way to confirm your login. This is quicker than typing a code, and your authenticator app stays available as a backup.

1. Add a new passkey

On the Multi-factor Authentication tab, under Passkey, select Add a new Passkey.

Multi-factor Authentication tab with the Add a new Passkey button circled

2. Name it and register

Give the passkey a name that tells you which device it is, such as “My MacBook” (1). Then select Register your passkey (2).

Add passkey screen with the Title field marked 1 and the Register your passkey button marked 2

Your browser will ask where to save the passkey and ask you to touch the fingerprint sensor or look at the camera. Follow the prompts.

When you are done, your passkey appears in the list.

Passkey section showing the new passkey named My MacBook circled

A passkey only works on the device, or the password manager account, where it was saved. Register a passkey on each computer you use, and keep your authenticator app set up for everywhere else.

What Changes When You Log In?

You will still enter your username and password as usual. After that, Joomla asks you to confirm it is you.

Using your authenticator app

Open your authenticator app, find the entry for your website, and type the current six-digit code into the box (1). Then select Validate (2).

Multi-factor Authentication login screen with the code field marked 1 and the Validate button marked 2

These codes change automatically, so you do not need to remember or save them.

Using a passkey

If you set up a passkey, select Select a different method.

Multi-factor Authentication login screen with the Select a different method button circled

Select Passkey. (You can also choose Backup Codes here if you do not have your phone.)

Select a Multi-factor Authentication method screen with Passkey circled

Select Validate with your passkey, then touch your fingerprint sensor or look at the camera when your browser asks.

Passkey login screen with the Validate with your passkey button circled

Getting a New Phone?

Before removing or resetting your old phone, make sure your authenticator codes have moved to your new phone (most apps have a transfer or cloud backup option), or add another method such as a passkey to your account.

If you lose access to your authenticator and have no passkey or backup code available, you may be unable to log into your website.

Need Help?

If you have trouble setting up MFA or are unsure whether it is working correctly, contact interGen support at This email address is being protected from spambots. You need JavaScript enabled to view it. or open a support ticket.

Please do not send passwords, verification codes, QR codes, or backup codes by email.