Skip to main content
Average reading time: 14 minutes, 52 seconds
Total Votes: 1
Please Rate
Decorative image about how to secure a joomla site

2. Lock down administrator access

The administrator login is the most attacked URL on any Joomla site. Protect it with two independent layers: Joomla's own multi-factor authentication, and a server-level lock in front of /administrator.

Enforce MFA for privileged groups

Joomla has shipped MFA in core since 4.2, with TOTP authenticator apps, WebAuthn/passkeys, YubiKey and email codes. Making it optional is not enough. Enforce it.

  1. Go to Users → Manage → Options → Multi-factor Authentication.
  2. In Enforce MFA for User Groups, select Super Users and Administrator (and Manager if they have backend access).
  3. Keep Maximum MFA tries low (the default is 10; 5 is a sensible value).

Tested: with enforcement on for Super Users, a correct username and password returned a 307 redirect to com_users&view=methods ("Multi-factor Authentication is mandatory for your user account"). A direct request to the User Manager was redirected to the same page. The account cannot reach anything until a second factor is set up.

If you are still on a version older than 5.4.9 / 6.1.4, disable the System - Remember Me plugin until you update. One of the September 2026 fixes was an MFA bypass through remember-me cookies.

Add a server-level lock in front of /administrator

A second, independent lock means a leaked Joomla password alone is not enough, and it hides the login form from bots. Create administrator/.htaccess:

# Second lock on the administrator area (HTTP Basic auth, HTTPS only)
AuthType Basic
AuthName "Restricted"
AuthUserFile /etc/apache2/.htpasswd-joomla
Require valid-user

Create the password file outside the web root with htpasswd -c /etc/apache2/.htpasswd-joomla <username>.

Tested: no credentials → 401, wrong credentials → 401, correct credentials → 200. The front end (200) and the API were unaffected, the default front end makes no requests to /administrator, and the full Joomla login worked through the extra layer. Rewrite rules from the root .htaccess still applied inside /administrator.

If your team has fixed IPs, Require ip 203.0.113.10 is a stronger alternative to Require valid-user. Behind Cloudflare or another proxy, Apache sees the proxy's IP, so use Basic auth instead.

Accounts and passwords

  • Do not use admin as a username. Give each person their own account; never share a Super User login.
  • Keep Super User to one or two people. Day-to-day editors belong in Editor, Publisher or Manager.
  • Users → Options → Password Options: the default minimum length on 6.1.4 is 12 characters with no other requirements. Raising the length to 14+ does more than requiring symbols.
  • Keep Allow User Registration off (the default) unless the site needs it.

Share this article