• Mar 24, 2026
  • --

Magnolia security best practices

Key insights

  • Centralized trust: Use the new Magnolia Trust Center for on-demand access to compliance reports and security documentation.

  • Proactive defense: Implement defense-in-depth strategies, from OS-level restrictions to AI-powered threat monitoring.

  • Verified compliance: Magnolia is officially SOC 2 Type 2 compliant, providing independent verification of our security controls.

  • Identity management: Prioritize Single Sign-On (SSO) and modern authentication protocols to secure author and public instances.

We built Magnolia DXP with security as a foundational principle, not an afterthought. In today’s landscape, website security is a fundamental necessity for building trust and ensuring the integrity of digital experiences. Whether you are managing sensitive customer data or public-facing content, a strong security posture protects your brand from reputational damage and operational disruptions.

This guide summarizes the essential security configurations and best practices we recommend to keep your Magnolia DXP projects secure.

Access security

Managing who can access your system is your first line of defense. We recommend moving away from manual account management toward centralized, automated systems.

  • Deactivate the superuser: One of the simplest yet most critical steps is to deactivate the default superuser account. Create a new account with the superuser role using a unique, non-obvious name.

  • Enforce strong password policies: We recommend following the latest NIST Password Guidelines. This means moving away from arbitrary complexity rules (like requiring a special character every 90 days) toward longer passphrases and checking against known password blacklists.

  • Implement Single sign-on (SSO): For enterprise environments, we recommend using our SSO module. This allows you to manage users in a central Identity Provider (IDP) like Azure AD, Okta, or Keycloak.

  • Restrict AdminCentral access: On production instances, block access to the Magnolia AdminCentral from the public internet. Use a VPN to ensure only authorized team members can access the authoring environment.

  • Use tokens for APIs: If you use custom REST endpoints or APIs, do not share usernames and passwords. Use tokens provided by your IDP to ensure secure, scoped access.

Verified trust: SOC 2 Type 2 compliance

We are pleased to share that Magnolia DXP is officially SOC 2 Type 2 compliant. While a Type 1 report is a snapshot of security, Type 2 proves that our controls were operating effectively over an extended period.

This certification validates our commitment to the five "Trust Service Criteria":

  1. Security: Protection against unauthorized access.

  2. Availability: Ensuring the system is available for operation and use.

  3. Processing Integrity: System processing is complete, valid, and accurate.

  4. Confidentiality: Information designated as confidential is protected.

  5. Privacy: Personal information is collected, used, and retained appropriately.

To prove our "transparency-first" approach, we have launched the Magnolia Trust Center. You can now access our full SOC 2 Type 2, ISO 27001, and ENS reports immediately without waiting for manual email replies.

External user management and SSO with Magnolia DXP

Single sign-on (SSO) allows users to log in to applications using the same credentials for multiple applications, making it easier to manage user accounts across your IT landscape.

Read now

Technical reality: Multi-layer protection

Magnolia DXP employs a "defense-in-depth" strategy. We expect individual layers to be challenged, so we build multiple safeguards:

  • Encryption at rest and in transit: We support AES 256 for data at rest and TLS v1.2/v1.3 for data in transit.

  • Web defacement protection: For high-stakes public sites, we offer 24/7 monitoring that takes snapshots of your pages and alerts you to unauthorized changes instantly.

  • AI-powered answers: The Trust Center includes an integrated chatbot to give you immediate, technical answers to specific security questions.

Summary and resources

Security is a shared responsibility. While we ensure the base platform is a "fortress," the configurations you choose—from password strength to API permissions—complete the picture. By following these best practices and utilizing the resources in the Magnolia Trust Center, you can focus on delivering great experiences while we help you maintain a secure foundation.
In addition, you can review the documentation below for more details:

FAQs

About the author

Cass Weber

Professional Services Manager, Magnolia

Cass oversees Services tasks and ensures a smooth and successful delivery. She started as a trainer and still provides training and helps out coordinating various training offering.