Get a free website with any plan

See how
WORDPRESS

Two-factor authentication for wp-admin

Last updated

IN SHORT

You can secure wp-admin on Flashcloud by installing the free Two-Factor plugin from WordPress core contributors. It pairs your login with an authenticator app like Google Authenticator or 1Password. A stolen password is no longer enough to access your site, because logging in requires a rotating six-digit code or a saved backup code.

You add two-factor authentication to wp-admin with a free plugin. The Two-Factor plugin from the WordPress core contributors team is the fastest route. Install it from wp-admin → Plugins → Add New, search "Two-Factor," activate it, then set it up under Users → Your Profile → Two-Factor Options. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password), save your backup codes somewhere safe, and you're covered.

2FA matters most for the account that can install plugins, edit files, and touch the database, which is exactly what wp-admin gives an attacker who gets your password. A stolen or guessed password stops being enough once a second factor is required.

Setting up TOTP-based 2FA

TOTP (time-based one-time password) is the standard approach: your authenticator app and WordPress both generate a rotating 6-digit code from a shared secret. Neither needs internet access to work after setup, and it doesn't depend on SMS, which can be intercepted or SIM-swapped.

  1. Install and activate the Two-Factor plugin.
  2. Go to Users → Your Profile, scroll to the two-factor section, and choose Authenticator App (TOTP).
  3. Scan the QR code with your authenticator app. Enter the 6-digit code it generates to confirm the pairing.
  4. Save the backup codes it gives you. Print them, or store them in a password manager, not a text file on the same computer you log in from.
  5. Repeat for every admin and editor account. 2FA on one account and not the others leaves an open door.

Once it's on, logging in asks for your password, then the code from your app.

Enforcing it account-wide

An admin who never sets up 2FA is a gap. The Two-Factor plugin lets you require it for specific roles: go to the plugin's settings and restrict login to accounts with 2FA enabled for Administrator and Editor roles at minimum. Give existing users a short grace period (a week is reasonable) so nobody gets locked out mid-session while you roll it out.

If you manage a WooCommerce store, this is worth doing before anything else on your security checklist. See Running a WooCommerce store for the broader picture on why store admin accounts need tighter controls than a blog.

Test it on staging first

2FA plugins hook into the login flow, and a misconfigured one can lock you out of your own site. Before requiring it account-wide on a live store or business site, set it up on a staging copy first: create a clone, enable and test the full login flow there, including what happens if you cancel out of the authenticator step. See Using WordPress staging for how to spin one up. Once you've confirmed login, logout, and recovery all work as expected, roll the same setup out to production.

If you get locked out

Losing your phone or authenticator app is the main risk with TOTP. Your backup codes are the first line of recovery, each one logs you in once in place of a TOTP code. If you didn't save them, or they're exhausted, you'll need direct database or file access to disable the plugin:

  • Open File Manager from your service's Manage Account tiles and rename the 2FA plugin's folder inside wp-content/plugins/. This typically deactivates the plugin, which drops the 2FA requirement without touching anything else.
  • Log back in with just your password, fix or reconfigure 2FA, then rename the folder back (or reinstall the plugin) to re-enable it.

On most hosting accounts, nightly backups mean a recent restore point already exists if a lockout happens alongside other trouble.

When to contact support

If you're locked out of both wp-admin and your hosting File Manager, or you're not comfortable editing files directly, open a ticket from Support in the portal. It's a real person, not a bot, and they can help you get back into your files without guessing at commands on a live site.

Common questions

What if I lose my phone and cannot log in?

Use one of your saved backup codes to log in immediately. If you have no backup codes left, log into your hosting File Manager and rename the plugin folder inside wp-content/plugins to deactivate the requirement.

Which authenticator apps can I use?

You can use Google Authenticator, Authy, or 1Password. The plugin uses standard TOTP technology to generate rotating six-digit codes.

Can I require other users on my site to use 2FA?

Yes, the plugin settings allow you to enforce two-factor authentication for specific roles like Administrator and Editor. Give existing users a grace period of about a week so they do not get locked out while setting it up.

Does the authenticator app require cell service or internet?

No, neither the authenticator app nor WordPress needs internet access to generate and check codes after setup. TOTP generates codes locally from a shared secret and does not rely on SMS.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.