Adding a second factor where passwords remain.
WHERE IT APPLIES
Control panel logins: cPanel, WHM and alternatives all support it
Your hosting provider's client area SSH, where it can be configured alongside keys
SSH WITH KEYS
Key authentication is already strong. Adding a second factor is possible and occasionally required by policy, but the practical gain over a passphrase-protected key is modest.
The higher-value targets are the control panel and the provider account, because those can rebuild or delete the server.
ENABLING IT ON THE CONTROL PANEL
WHM and cPanel both offer two-factor authentication using an authenticator app. Enable it for root and for every reseller or administrative account.
Store the backup codes somewhere other than the server.
ON YOUR PROVIDER ACCOUNT
Enable it. Someone with access to your provider account can reinstall the operating system, which destroys everything.
FOR TEAMS
Each person enables it on their own account. Shared accounts make this impossible, which is another reason not to have them.