Knowledgebase

Enabling Two-Factor Authentication on WordPress Print

  • wordpress, twofactor, plugins, backup, password, cpanel, filemanager, woocommerce
  • 0

Two-factor authentication (2FA) requires a one-time code from your phone in addition to your password. It is the single most effective protection against stolen or guessed credentials.

Setup

  1. Install a plugin that provides 2FA — Two Factor, WP 2FA, or the feature built into Wordfence.
  2. Install an authenticator app on your phone: Google Authenticator, Microsoft Authenticator or Authy.
  3. In WordPress go to Users → Profile and find the two-factor section.
  4. Choose the app-based (TOTP) method and scan the QR code with your authenticator app.
  5. Enter the six-digit code shown in the app to confirm, then save.

Save your backup codes

Every 2FA plugin offers a set of one-time backup codes. Download or print them and store them somewhere other than the site. They are your only way back in if you lose the phone.

Enforce it for all admins

Most 2FA plugins can require 2FA by role. Enforce it for Administrator and Editor at minimum.

If you are locked out

Rename the 2FA plugin's folder in wp-content/plugins/ using cPanel File Manager. That deactivates it and lets you log in with your password alone, after which you can reconfigure it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot