Choose How QCBM Handles the Joomla Administrator Account During Recovery
When a recovery includes the database, the QCBM Recovery Runner can leave administrator accounts unchanged, reset an existing Super User, or create a temporary Recovery Super User.
Use the least invasive option that still guarantees you can securely access the recovered Joomla administrator.
Option 1: Keep Existing Administrator Accounts Unchanged
Choose Keep existing administrator accounts unchanged when you know a valid Super User login will work after recovery.
This is the simplest option because QCBM does not alter administrator credentials or create a recovery account.
Option 2: Reset an Existing Super User
Choose Reset an existing Super User when the account exists in the recovered database but you need to restore access. Identify the account by Super User ID, username, or email.
You may provide a new username and email or leave them blank to keep the existing values. Enter a new password of at least 10 characters.
Option 3: Create a Temporary Recovery Super User
Choose Create a temporary Recovery Super User when you cannot rely on an existing administrator account. Supply the requested username, email, and password.
The temporary account is marked for password reset. Treat it as emergency access, not as a permanent unnoticed administrator identity.
When the Administrator Options Appear
Administrator recovery is relevant when the selected recovery mode includes the database. Files-only recovery does not restore Joomla user records, so QCBM does not present the database administrator-recovery controls for that mode.
Security Practices
- Use a unique recovery password and keep it out of tickets, screenshots, or shared notes.
- Do not create a temporary Super User if an existing verified account already provides safe access.
- After validation, rotate any emergency password that should not remain in use.
- Remove a temporary recovery account when it is no longer required.
- Review Joomla's Super User list after recovery so there are no unexpected privileged accounts.
Administrator Access Gates Still Apply
If the site normally protects /administrator/ with an IP rule, secret URL parameter, WAF, or another access gate, use that normal protected access method after recovery. The Recovery Runner's administrator-account option does not bypass external administrator protection.
Verify Administrator Recovery
- Complete the recovery.
- Open the administrator using the site's normal protected access method.
- Sign in with the account strategy you selected.
- Confirm the account has expected Super User access.
- Rotate/remove temporary credentials as appropriate.
- Only then check I confirmed that the restored frontend and administrator are working.
Community Discussion
Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.