Two-Factor Authentication and Staff Permissions on Shopify
Table of Content
A fashion label in Surry Hills had what they thought was a smart setup. Five staff, each with their own Shopify login, and a shared spreadsheet listing who could do what. The reality, when we ran an audit, was that all five accounts had full admin access, two were ex employees who had moved on six months earlier, and 2FA was enabled on exactly one account: the founder’s. When her assistant’s personal Gmail was breached in an unrelated data leak, the same password worked on Shopify, and an attacker spent ninety minutes inside the admin before anyone noticed. The damage was limited, but only by luck.
Two factor authentication and well designed staff permissions are the two controls that would have stopped that incident before it started. They are also the two areas where almost every Shopify merchant we work with has room to improve. This article walks through how to set both up properly.
Why 2FA matters more than a strong password
Password reuse is universal. Even people who know better do it, because remembering forty unique passwords is unrealistic without a password manager, and password managers still have not reached majority adoption. When a breach on an unrelated site exposes an email and password combination, attackers run it against thousands of services automatically. Shopify is on the list. Without a second factor, that single leaked credential is enough.
2FA breaks that chain. Even with a valid password, the attacker needs a second piece of evidence that you control. The cost to you is a few seconds at login. The cost to them is enormous.
Choosing a 2FA method on Shopify
Shopify supports three options, and they are not equal.
- SMS codes: better than nothing, but vulnerable to SIM swapping. Australian telcos have tightened their processes, but determined attackers still pull off port outs by impersonating the account holder. Use SMS only as a fallback.
- Authenticator apps (TOTP): the practical default. Apps like 1Password, Authy, Google Authenticator and the Shopify mobile app generate time based codes on your device. There is no network dependency, no SIM risk, and the user experience is smooth.
- Hardware security keys (FIDO2 / WebAuthn): the strongest option. A physical key like a YubiKey or a Titan key plugs into USB or taps via NFC. Phishing resistant by design, because the key will only authenticate to the real Shopify domain. Worth the spend for owner, finance and developer accounts.
Our recommendation for most Australian Shopify stores: TOTP for all staff as a minimum, hardware keys for anyone who can touch money or code.
Enforce 2FA across the organisation
Shopify Plus stores can require 2FA for every staff account from the organisation settings. For non Plus stores, the requirement is per account, which means you need to verify enrolment manually. Open the staff list, check the 2FA column for every name, and follow up with anyone who has not enabled it. Make it a hiring step: no production access until 2FA is on. We have seen too many audits where the policy existed but enforcement did not.
Designing staff roles around least privilege
Least privilege is a simple idea: give each person the minimum access they need to do their job, and nothing more. The benefit is twofold. If a credential is compromised, the blast radius is smaller. If a staff member makes a mistake, the worst they can do is also smaller.
Shopify lets you build custom permission sets covering products, orders, customers, marketing, analytics, apps, themes, settings and more. Map out the actual jobs in your store, and then build a role for each one. Some patterns we use:
- Customer service: orders, customers, draft orders, gift cards. No settings, no apps, no themes.
- Marketing: products, collections, discounts, marketing, online store content. No customers (unless they truly need exports), no settings.
- Finance: reports, payouts, billing. No content editing, no app installs.
- Developer: themes, apps, settings. Limited customer access. Often a separate account from a daily login.
- Owner: full access. Used rarely, like a break glass credential.
The owner account deserves special treatment. It is the only role that can change payouts, transfer ownership and remove other owners. If you can avoid using it day to day, do. Create yourself a staff account with the permissions you actually need, and keep the owner credentials in a password manager with a hardware key.
Audit logs: turn them on, then actually read them
Shopify keeps a staff actions log that records logins, permission changes, app installs, theme edits, payout changes and more. On Shopify Plus, the retention is longer and the export options are better. On non Plus, you still get the basics.
Set a calendar reminder to review the log monthly. Look for logins from unfamiliar locations, after hours activity, and permission changes you do not remember approving. Most of the time you will see nothing interesting. The one time you do, you will be glad you looked.
Offboarding: the step everyone skips
The Surry Hills story above turned on two ex employees who still had access. This is the single most common finding in our Shopify audits. People leave, the founder means to revoke access, and a week becomes a month becomes six months. Make offboarding a checklist that runs the same day someone’s last day is confirmed.
- Remove the staff account from Shopify.
- Revoke any custom app tokens that staff member created.
- Rotate any shared secrets (rare in well designed stores, but they exist).
- Check connected services: email platform, helpdesk, analytics, BNPL providers.
- Note the change in the audit log so you have a record.
Contractors and agencies need the same treatment. When a project ends, their access ends. If they come back next quarter, you can re add them.
Common mistakes we see
Three patterns come up repeatedly when we audit Shopify stores.
- Shared logins: two people using the same staff account so that you can save a seat. The audit log becomes useless because every action looks like the same person. Always one account per person.
- The “just give me admin” trap: a contractor needs to do one task and asks for full access “just for today.” The today becomes forever. Build a contractor role and use it.
- 2FA recovery codes left in inboxes: Shopify gives you recovery codes when you enrol in 2FA. Storing them in your email defeats the entire point. Put them in a password manager or on paper in a locked drawer.
A 30 minute action plan
If you do nothing else after reading this, give yourself half an hour today and run through these steps.
- Open the Shopify staff page and list every account.
- Remove anyone who should not be there.
- For everyone who remains, check that 2FA is enabled. Chase anyone missing.
- Review the permissions on each account against their actual job. Tighten where you can.
- Enable an authenticator app on your own account if you are still on SMS.
- Order two hardware keys for the owner account (one as a backup).
That single half hour will move your store from average to genuinely well protected.
Where Defyn fits in
If you would rather have someone walk through your Shopify access controls with you, our team does this regularly as part of broader audits. We cover access, app permissions, fraud configuration and edge protection together, alongside performance work like Shopify mobile speed optimisation. Have a look at our Sydney web development services or start a project to scope a review. For ongoing checks, our audit and support retainer includes quarterly access reviews so nothing drifts.
Want your access controls, apps and fraud settings reviewed properly? Security hardening is part of our Shopify development services.
