2. Lock down administrator access
The administrator login is the most attacked URL on any Joomla site. Protect it with two independent layers: Joomla's own multi-factor authentication, and a server-level lock in front of /administrator.
Enforce MFA for privileged groups
Joomla has shipped MFA in core since 4.2, with TOTP authenticator apps, WebAuthn/passkeys, YubiKey and email codes. Making it optional is not enough. Enforce it.
- Go to Users → Manage → Options → Multi-factor Authentication.
- In Enforce MFA for User Groups, select Super Users and Administrator (and Manager if they have backend access).
- Keep Maximum MFA tries low (the default is 10; 5 is a sensible value).
Tested: with enforcement on for Super Users, a correct username and password returned a 307 redirect to com_users&view=methods ("Multi-factor Authentication is mandatory for your user account"). A direct request to the User Manager was redirected to the same page. The account cannot reach anything until a second factor is set up.
If you are still on a version older than 5.4.9 / 6.1.4, disable the System - Remember Me plugin until you update. One of the September 2026 fixes was an MFA bypass through remember-me cookies.
Add a server-level lock in front of /administrator
A second, independent lock means a leaked Joomla password alone is not enough, and it hides the login form from bots. Create administrator/.htaccess:
# Second lock on the administrator area (HTTP Basic auth, HTTPS only)
AuthType Basic
AuthName "Restricted"
AuthUserFile /etc/apache2/.htpasswd-joomla
Require valid-user
Create the password file outside the web root with htpasswd -c /etc/apache2/.htpasswd-joomla <username>.
Tested: no credentials → 401, wrong credentials → 401, correct credentials → 200. The front end (200) and the API were unaffected, the default front end makes no requests to /administrator, and the full Joomla login worked through the extra layer. Rewrite rules from the root .htaccess still applied inside /administrator.
If your team has fixed IPs, Require ip 203.0.113.10 is a stronger alternative to Require valid-user. Behind Cloudflare or another proxy, Apache sees the proxy's IP, so use Basic auth instead.
Accounts and passwords
- Do not use
adminas a username. Give each person their own account; never share a Super User login. - Keep Super User to one or two people. Day-to-day editors belong in Editor, Publisher or Manager.
- Users → Options → Password Options: the default minimum length on 6.1.4 is 12 characters with no other requirements. Raising the length to 14+ does more than requiring symbols.
- Keep Allow User Registration off (the default) unless the site needs it.
