> For the complete documentation index, see [llms.txt](https://help.steeple.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.steeple.com/en/mises-a-jour-produit/semaine-2026-05-11.md).

# Week of 06/15/2026 — Access to the Steeple store / Two-factor authentication

**🛍️ Navigation – Direct access to the Steeple Store**

Until now, administrators had no direct access to the Steeple Store from the interface, which could slow down ordering equipment or managing licenses. This change aims to simplify access to the store by integrating it directly into the main navigation, so organization administrators can manage their equipment and subscriptions without leaving Steeple.

🆕 What has been updated:

* **New “Store” item in the navigation** : accessible from the main navigation bar, just after “Administration”.
* **Access to the Steeple Store** : ordering touchscreens, boxes, and increasing the number of licenses directly from the interface.
* **Opening in a new tab** : the store opens without leaving the Steeple interface.
* **Targeted visibility** : the entry is reserved for organization administrators and is not visible to other users.

<figure><img src="https://608007981-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FByS0e17eM732OXdGGkme%2Fuploads%2FbOr0Ue57J9aFMVX71rt7%2Fimage.png?alt=media&amp;token=6613a95c-ce14-4a62-abc6-3f093803d277" alt=""><figcaption></figcaption></figure>

**🔐 Security – Two-factor authentication (2FA / TOTP)**

Until now, Steeple login relied solely on a username and password, with no additional security layer in the event of credential compromise. This change aims to strengthen account protection by offering two-factor authentication via temporary code (TOTP), for users who do not use SSO login.

🆕 What's been updated

* **Activation from account settings** : display of a QR code and a manual key to set up an authentication app (Google Authenticator, Authy, etc.).
* **Backup codes** : generation of downloadable or copyable codes to access the account in case the authentication device is lost.
* **OTP challenge at login** : accounts protected by 2FA are presented with a temporary code verification step at each login.
* **Administrator management** : administrators can disable a user's 2FA via a dedicated confirmation modal, to handle lockout situations.

ℹ️ Note: 2FA is available only for non-SSO logins.
