2FA for Portal Users
Let customers and partners protect portal accounts with two-factor verification codes
The auth_totp_portal module extends two-factor authentication to portal users so they can protect their accounts just like internal employees.
This is especially useful for portals containing orders, invoices, contracts, or other sensitive customer and partner data.
How portal users can use 2FA
Key points
• They can enable 2FA themselves from the portal security page when allowed.
• They can also receive an invitation email from an administrator to complete setup.
• They use the same authenticator apps as internal employees, such as Google Authenticator or Authy.
• Trusted devices are supported to reduce repeated code entry on personal devices.
Enable 2FA for a portal user
Steps
1. Sign in to the portal.
2. Open My Account or Security.
3. Find the Two-Factor Authentication section.
4. Click Enable Two-Factor Authentication.
5. Scan the QR code or enter the secret manually in the authenticator app.
6. Enter the current 6-digit code and click Enable to finish.
Set up from an administrator invitation
Steps
1. Open the email titled Invitation to use Two-Factor Authentication.
2. Click the link in the message.
3. The system redirects to the portal security page rather than the backend admin area.
4. Complete QR scanning and code verification just like the standard setup flow.
Sign in with 2FA
Steps
1. Open the portal page and enter the email and password.
2. Click Log in.
3. Open the authenticator app on the phone.
4. Enter the current 6-digit code.
5. Optionally check Remember this device if this is a personal machine.
6. Click Verify to complete sign-in.
Manage 2FA and trusted devices
Key points
• View 2FA status in My Account → Security.
• Disable 2FA if the system policy allows it.
• Review trusted devices and remove individual devices when needed.
• Use Revoke All Devices to force re-verification on every previously trusted machine.
Portal users vs internal employees
Quick comparison
| Feature | Portal User | Internal Employee |
|---|---|---|
| Setup page | /my/security or portal security page | Backend settings or internal profile page |
| Authenticator app | Same | Same |
| TOTP sign-in flow | Same | Same |
| Invitation email | Links to the portal | Links to the backend or internal interface |
Important notes
Key points
• Never share the setup secret or the 6-digit verification code with anyone else.
• Only mark trusted devices on personal machines.
• If administrators enforce 2FA, portal users cannot skip the setup step.
• Lost or replaced phones should be handled immediately to avoid login disruption.
Troubleshooting
Common issues
| Issue | Cause | Solution |
|---|---|---|
| No option to enable 2FA | Administrators have not granted access or the module is not installed | Ask an administrator to enable the feature or send an invitation. |
| Invitation link does not work | The link expired or points to the wrong portal | Request a new invitation or open the portal security page directly. |
| Verification code is incorrect | The code expired or the device clock is out of sync | Try the latest code and sync the phone time. |
| Phone is lost | No access to the authenticator app anymore | Ask an administrator to disable 2FA or allow setup again. |