ÃÛ¶¹ÊÓƵ

Security

There are multiple ways to secure your store and maintain your data security:

NOTE
Stores that have enabled ÃÛ¶¹ÊÓƵ Identity Management Services (IMS) authentication have native ÃÛ¶¹ÊÓƵ Commerce and Magento Open Source 2FA disabled. Admin users who are logged into their Commerce instance with their ÃÛ¶¹ÊÓƵ credentials do not need to reauthenticate for many Admin tasks. Authentication is handled by ÃÛ¶¹ÊÓƵ IMS when the Admin user logs into their current session. See ÃÛ¶¹ÊÓƵ Identity Management Service (IMS) Integration Overview.

Visit the to get the latest news about potential vulnerabilities, register for ÃÛ¶¹ÊÓƵ Security notifications, and access the ÃÛ¶¹ÊÓƵ Trust Center.

Security Center {width="700" modal="regular"}

For information about security best practices, see Secure your Commerce Site and Infrastructure in the Implementation Playbook.

Security action plan

If you suspect that your ÃÛ¶¹ÊÓƵ Commerce or Magento Open Source site is compromised, follow this action plan without delay.

  1. Diagnose: Run a scan to establish the security status of your Commerce store. Commerce Security Scan is a free service offered by ÃÛ¶¹ÊÓƵ that allows you to monitor your Commerce sites for known security risks and malware, and to receive security notifications.

  2. Clean: Hire a or online service to clean your site of all malicious code. Some Commerce community members recommend . Check the /media folder for leftover executable code. Remove all unknown Admin users and reset all Admin passwords.

  3. Protect: Keep your Commerce installation up to date with the most current release. If you are using an older version, apply all security patches as they become available. Review and follow . Subscribe to .

  4. Report: If you think that you have found a specific vulnerability in Commerce, and include technical details.

  5. Upgrade: For the additional peace of mind that comes from 24/7 support, plan your upgrade to now.

recommendation-more-help
d3c62084-5181-43fb-bba6-1feb2fcc3ec1