The Magento admin panel is the keys to the kingdom: it can change prices, export customer data, install extensions and edit CMS content. It is also scanned for constantly - bots probe for /admin and common custom paths on every store, every day. Securing it properly takes an afternoon and prevents the incidents that end careers.
Move the Admin Path
The default /admin path is the first thing every botnet tries. Set a custom path in env.php:
'backend' => [
'frontName' => 'management-x7k2'
],
Treat the path as a first line of defence, not real security - it reduces noise, it does not stop a targeted attacker.
Enforce Two-Factor Authentication
Magento 2.4 ships 2FA for admin users and it should be non-negotiable. It cannot be disabled via config on current versions, and that is correct. Verify every admin user has enrolled, and re-check after migrations - we have seen restored databases with 2FA bypass tables in odd states. (We cover the 2FA configuration options in detail in a separate post.)
Restrict by IP Where Possible
If your team works from fixed locations or a VPN, allowlist the admin path at the web server or CDN layer:
location ~ ^/management-x7k2 {
allow 203.0.113.0/24;
deny all;
}
On Fastly (Adobe Commerce Cloud) the same is done with an edge ACL. An attacker who cannot reach the login form cannot brute-force it.
Least-Privilege User Roles
Every admin user should have the smallest role that covers their job. Magento’s role system is granular - use it:
- Customer service gets Orders and Customers, nothing else
- Content editors get CMS and Catalog categories, not configuration
- Developers get a dedicated role for what they genuinely need in production (ideally: read access and logs, not system config)
Audit users quarterly. Disable accounts the day someone leaves, not the week after.
The Settings That Matter
- Admin session lifetime: shorten it; an 8-hour session on a shared laptop is a risk
- Password policy: enforce strong passwords and rotation via Stores > Configuration > Advanced > Admin
- Account sharing: forbidden. Shared logins destroy your audit trail - the action log is only useful when actions map to people
- Admin Action Log (Adobe Commerce): enable it for sensitive areas like payment config and user management
Watch the Edges
Most admin compromises we investigate came from one of three routes: a phished password without 2FA, a former staff account left active, or a third-party extension with an adminhtml vulnerability. 2FA, offboarding discipline and extension hygiene cover all three. None of them require spending money - just an afternoon and a recurring calendar reminder.