2FA for Portal Users

Let customers and partners protect portal accounts with two-factor verification codes

The auth_totp_portal module extends two-factor authentication to portal users so they can protect their accounts just like internal employees.

This is especially useful for portals containing orders, invoices, contracts, or other sensitive customer and partner data.

Portal
2FA
TOTP
Authenticator App
Trusted Device

How portal users can use 2FA

Key points

  • They can enable 2FA themselves from the portal security page when allowed.

  • They can also receive an invitation email from an administrator to complete setup.

  • They use the same authenticator apps as internal employees, such as Google Authenticator or Authy.

  • Trusted devices are supported to reduce repeated code entry on personal devices.


Enable 2FA for a portal user

Steps

  • 1. Sign in to the portal.

  • 2. Open My Account or Security.

  • 3. Find the Two-Factor Authentication section.

  • 4. Click Enable Two-Factor Authentication.

  • 5. Scan the QR code or enter the secret manually in the authenticator app.

  • 6. Enter the current 6-digit code and click Enable to finish.


Set up from an administrator invitation

Steps

  • 1. Open the email titled Invitation to use Two-Factor Authentication.

  • 2. Click the link in the message.

  • 3. The system redirects to the portal security page rather than the backend admin area.

  • 4. Complete QR scanning and code verification just like the standard setup flow.


Sign in with 2FA

Steps

  • 1. Open the portal page and enter the email and password.

  • 2. Click Log in.

  • 3. Open the authenticator app on the phone.

  • 4. Enter the current 6-digit code.

  • 5. Optionally check Remember this device if this is a personal machine.

  • 6. Click Verify to complete sign-in.


Manage 2FA and trusted devices

Key points

  • View 2FA status in My Account → Security.

  • Disable 2FA if the system policy allows it.

  • Review trusted devices and remove individual devices when needed.

  • Use Revoke All Devices to force re-verification on every previously trusted machine.


Portal users vs internal employees

Quick comparison

FeaturePortal UserInternal Employee
Setup page/my/security or portal security pageBackend settings or internal profile page
Authenticator appSameSame
TOTP sign-in flowSameSame
Invitation emailLinks to the portalLinks to the backend or internal interface

Important notes

Key points

  • Never share the setup secret or the 6-digit verification code with anyone else.

  • Only mark trusted devices on personal machines.

  • If administrators enforce 2FA, portal users cannot skip the setup step.

  • Lost or replaced phones should be handled immediately to avoid login disruption.


Troubleshooting

Common issues

IssueCauseSolution
No option to enable 2FAAdministrators have not granted access or the module is not installedAsk an administrator to enable the feature or send an invitation.
Invitation link does not workThe link expired or points to the wrong portalRequest a new invitation or open the portal security page directly.
Verification code is incorrectThe code expired or the device clock is out of syncTry the latest code and sync the phone time.
Phone is lostNo access to the authenticator app anymoreAsk an administrator to disable 2FA or allow setup again.