Requiring a secure sign-in method for all users in your organization

You can require all users in your organization to use a secure sign-in method to log in to your stores from the Users > Security page in your Shopify admin settings. Secure sign-in methods include passkeys and two-step authentication. If you don't require users in your organization to use a secure sign-in method, then the choice is left up to the user. Some users might not choose to use passkeys or two-step authentication for additional account security, which could put your organization at risk.

This setting covers a broader secure sign-in requirement that can be satisfied by supported methods such as passkeys or two-step authentication.

Only eligible users can access security settings.

Users that can't be required to use a secure sign-in method

A secure sign-in method can't be required for certain users. You can still set a secure sign-in method to be required for all users, but it won't be enforced for the following user types:

Managing users after requiring a secure sign-in method

After you require a secure sign-in method for all users in organization settings, individual users can't be managed separately. Changing your requirement setting to individual user management afterwards doesn't revert their login requirements, but does allow users to be managed individually if you want to remove the secure sign-in method requirement.

For example, suppose that a user in your organization, Phillipa, isn't required to use a secure sign-in method. You then activate the requirement for your organization. All your users, including Phillipa, are now required to use a secure sign-in method to log in. Later, you change your requirement setting back to managing specific users. Phillipa's user accounts are still set to require a secure sign-in method for all stores in your organization. If you want to remove the requirement, then you can do so through Phillipa's user page.

Users with SAML authentication

Because a secure sign-in method can be required through an identity provider, users that are required to use SAML authentication aren't affected by this setting. If the SAML requirement is removed from these users and you require a secure sign-in method in your organization, then they will be required to use a secure sign-in method after the change is made.

Example of SAML authentication and the requirement

For example, suppose that you activate the secure sign-in method requirement for your organization. You have a user, Emmy, who is required to use SAML authentication to log in. Later, you remove Emmy's SAML requirement. Emmy is automatically required to use a secure sign-in method to log in from that point on.

Activate the secure sign-in method requirement

Steps:

  1. From your Shopify admin, go to Settings > Users.

  2. Click Security.

  3. In the Secure sign-in method section, click Change.

  4. Select Required for all users.

  5. Click Save.

Requiring a secure sign-in method takes some time, depending on how many users are in your organization. A banner displays on the Security page indicating that your changes are in progress, and you'll receive an email when the process is complete. The email will also note whether there were any errors during the process, and list all users that aren't fully enforced.

Manage errors

When you activate the secure sign-in method requirement, every user account in all your stores is set to require a secure sign-in method. As a result, it's possible for the process to complete for some users but not for others, and for some users to have different login requirements in different stores.

For example, suppose that in your organization you have three stores. You activate the secure sign-in method requirement, and after the process is complete, you receive an email stating that your changes didn't complete for one of your users, Daveed. In this state, every user in your organization except Daveed needs to use a secure sign-in method to log in. This means that although Daveed might need to use a secure sign-in method for some of your stores, there are other stores where Daveed can log in without authenticating with a secure method.

If you receive an error after activating the secure sign-in method requirement, then try activating the requirement again.

Steps:

  1. From your Shopify admin, go to Settings > Users.

  2. Click Security.

  3. In the Secure sign-in method section, click Try again.

If requiring a secure sign-in method for one of your users fails repeatedly, then contact Shopify Support.

Deactivate the secure sign-in method requirement

Deactivating your secure sign-in method requirement doesn't remove your user's existing login requirements. This means that all of your affected users with a secure sign-in method are still required to log in using that method.

However, you can adjust the secure sign-in method requirement for individual users and remove the requirement for specific users.

After you switch to Specific users, new users you invite still have the secure sign-in method requirement turned on by default. To exempt a new user, turn off the requirement for them during the invite, or from their user page.

You can't remove the secure sign-in method requirement for all users in bulk. You must take the additional step of manually adjusting the requirement for each user to be not required.

You need to repeat these steps for every user that you want to remove the secure sign-in method requirement for.

Steps:

  1. From your Shopify admin, go to Settings > Users.

  2. Click Security.

  3. In the Secure sign-in method section, click Change.

  4. Select Specific users.

  5. Click Save.

  6. Click Users.

  7. Click the user that you want to remove the secure sign-in method requirement for.

  8. In the Secure sign-in method section, select Secure sign-in method is not required.

  9. Click Save.