Two-factor sign-in
The second factor for the backoffice — why it belongs there and not with the learners.
Where the risk sits
A hijacked learner account costs one course access. A hijacked backoffice account costs courses, orders, customer data and the payment settings. So the protection belongs where the damage occurs.
What that means day to day
Anyone entering the backoffice additionally identifies themselves through an authenticator app. Setup runs once via a QR code; after that it is a glance at the phone.
Two separate worlds
Operators and learners are two separate account types, not one table with a role column. Mixing them up here is the classic origin of permission bugs — it cannot happen, because the two paths never meet.
What applies to learners
For them sign-in stays simple. Demanding a second factor there too loses buyers at the checkout while protecting nothing that does not already belong to the buyer.