How to enable 2FA as an Admin/Staff
- Go to My Account > Security.

- Scroll down to Two-Factor Authentication and click Enable.

- Open your authenticator app (e.g., Google Authenticator) on your mobile device and scan the QR code, or use the provided link.

- Enter the generated code in the field and click Enable.
Authenticator apps generate a new code every 30 seconds. Enter it before it expires.


How to disable 2FA as an Admin/Staff
- Go to My Account > Security and click Disable.

- Open your authenticator app and find the current code for your Upmind account.
- Enter the code in the provided field on the Security page.

- Click Disable on the confirmation pop-up to confirm.

Enforcing 2FA for Clients
Admin/Staff can require all clients to set up 2FA when they log in.- Go to Settings > Client Auth Providers under Users and Permissions.

- Click the three dots (⋮) next to the relevant auth provider and select Edit.

- Toggle on Enforce 2FA on Login.


Impersonating a Client to activate 2FA
Admins/Staff can impersonate a client account to activate 2FA on their behalf.- Select the client and impersonate them.

- Go to My Account > Security.
- Follow the same steps under Enabling 2FA above.

When staff impersonates a client to make changes, 2FA verification is not required from the staff side. So, only the client triggers the 2FA check when changing their own credentials.
2FA when changing your password or email
Upmind requires a verification code any time an admin or staff member changes their own password or email address. This is enabled by default across all brands.Updating password from account security
When you submit a password or email change, Upmind will send a 6-digit verification code to your current email address. The request won’t go through until you enter that code.- Submit the password or email change as normal from My Account > Security.

- Enter the 6-digit code you received in the verification field.
- Submit again to complete the change.
This verification step does not apply when an administrator changes another staff member’s credentials. It only applies when you are changing your own.
Resetting password from login
- Click Forgotten your password.

- You will receive an email to reset your password. Click the link.

- Now, when you try to reset your password, you will be prompted to enter your 2FA code.

Resetting 2FA after losing your authenticator
If you lose access to your authenticator app, another account administrator can reset your 2FA from the admin panel. If no other administrator is available, send an email to support@upmind.com from the address registered on your Upmind account and the support team will help restore your access.Enforcing email verification before checkout
You can require clients to verify their email address before they can place an order. This helps confirm contact information and reduces the risk of fraudulent orders.How it works
The verification check applies at the start of the checkout process, and it does not block registration. Clients can register, return to their basket, and browse without verifying, but they must complete email verification before they can proceed to checkout. To enable this setting- Go to Settings > Security under Branding and Customisation.

- Enable Require a verified email to place an order.




