B2C Commerce provides five security stages in Business Manager that allow merchants to control the pace of their migration. Navigate to Administration > Global Preferences > Security in Business Manager to view and change your current stage.
| Stage | Name | Behavior | User Impact |
| 0 | No Unified Authentication | Feature disabled | Users log in with Business Manager credentials only |
| 1 | Unified Authentication Supported | Admins can test the unified login URL | No impact to end users |
| 2 | Unified Authentication Encouraged | Users prompted to link accounts on login | Linking is optional; Business Manager credentials still work |
| 3 | Unified Authentication Mandatory | Users must link accounts before proceeding | Users without linked Account Manager accounts are blocked from logging in |
| 4 | Unified Authentication Only | Only Account Manager login accepted | Business Manager credential login is fully retired |
With the 21.6 Commerce Release, all Business Manager instances automatically migrated to Stage 2 — Unified Authentication Encouraged. At this stage:
With the 21.8 Commerce Release, all Business Manager instances migrated to Stage 3 — Unified Authentication Mandatory. At this stage:
System users (also called automation users or service accounts) that perform automated tasks against Business Manager — such as scheduled jobs, import/export processes, or API integrations — cannot be migrated to Unified Authentication. These users must instead authenticate using Access Keys.
To generate an Access Key for a system or automation user:
After Unified Authentication is enabled, the following access points no longer accept Business Manager username/password credentials. All require Access Key authentication using your Account Manager login and a generated Access Key:
Access Key format for these access points:
Username: <your-account-manager-email>
Password: <your-generated-access-key>
Business Manager provides a Migration Status section within the Security settings screen that shows:
To view migration status, navigate toAdministration > Global Preferences > Securityin Business Manager and scroll to the Migration Status section.
A development team uses WebDAV clients (such as Cyberduck or a VS Code WebDAV extension) to deploy cartridges to B2C Commerce. After Unified Authentication is enforced at Stage 4, the team's existing WebDAV connections using Business Manager credentials stop working. The correct resolution is to generate Access Keys in Account Manager for each developer and update the WebDAV client configuration to use the Account Manager email as the username and the Access Key as the password.
A merchant's Business Manager instance is currently at Stage 2 (Unified Authentication Encouraged). The merchant administrator has 45 Business Manager users, of whom 30 have already linked their Account Manager accounts. The administrator uses the Migration Status screen (Administration > Global Preferences > Security) to identify the 15 users who have not yet linked, and sends Account Manager invitation emails to those users before the 21.8 release enforces Stage 3.
A Business Manager user did not link their Account Manager account before Stage 3 was enforced. They attempt to log in and are blocked with an error. The merchant administrator must create an Account Manager account for the user, assign the appropriate B2C Commerce realm and roles, and inform the user to log in via Account Manager at <REDACTED>.
Issue: A user cannot log in to Business Manager after Stage 3 or Stage 4 is enforced.
Cause: The user's Business Manager account is not linked to an Account Manager account.
Resolution: The merchant administrator must create or locate the user's Account Manager account and assign them to the correct B2C Commerce realm with the appropriate roles. The user then logs in via Account Manager (<REDACTED>) to access Business Manager.
Issue: WebDAV, OCAPI, or Studio connections fail after enabling Unified Authentication.
Cause: These access points no longer accept Business Manager username/password credentials after migration.
Resolution: Generate an Access Key in Account Manager for the affected user or system account. Use the Account Manager email as the username and the Access Key as the password in the integration or client configuration.
Issue: The Security Stage selector is not visible in Business Manager.
Cause: The Business Manager user account does not have the Administrator role, or the instance has already reached Stage 4 (Unified Authentication Only) and the selector is no longer displayed.
Resolution: Confirm the logged-in user has the Administrator role in Account Manager. If the instance is at Stage 4, no further stage changes are possible — this is expected behavior.
000390265

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.