Slide 36
Slide 36 text
● If you can, IP lock the control panel
○ Cloudflare calls this “Zone Lockdown”
○ Can also be done in .htaccess/nginx config, or a plugin
● If you can’t IP lock the control panel:
○ Consider turning ‘preventUserEnumeration’ to true
■ Possibly more confusing for some users but more secure
○ Change cpTrigger from “admin”, which is often scanned
● Consider tying Craft login to SSO - Google, Okta, etc…
○ Via plugin, Cloudflare Access, or similar
● Weak user passwords are your biggest threat
Security