You add two-factor authentication to wp-admin with a free plugin. The Two-Factor plugin from the WordPress core contributors team is the fastest route. Install it from wp-admin → Plugins → Add New, search "Two-Factor," activate it, then set it up under Users → Your Profile → Two-Factor Options. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password), save your backup codes somewhere safe, and you're covered.
2FA matters most for the account that can install plugins, edit files, and touch the database, which is exactly what wp-admin gives an attacker who gets your password. A stolen or guessed password stops being enough once a second factor is required.
Setting up TOTP-based 2FA
TOTP (time-based one-time password) is the standard approach: your authenticator app and WordPress both generate a rotating 6-digit code from a shared secret. Neither needs internet access to work after setup, and it doesn't depend on SMS, which can be intercepted or SIM-swapped.
- Install and activate the Two-Factor plugin.
- Go to
Users → Your Profile, scroll to the two-factor section, and choose Authenticator App (TOTP). - Scan the QR code with your authenticator app. Enter the 6-digit code it generates to confirm the pairing.
- Save the backup codes it gives you. Print them, or store them in a password manager, not a text file on the same computer you log in from.
- Repeat for every admin and editor account. 2FA on one account and not the others leaves an open door.
Once it's on, logging in asks for your password, then the code from your app.
Enforcing it account-wide
An admin who never sets up 2FA is a gap. The Two-Factor plugin lets you require it for specific roles: go to the plugin's settings and restrict login to accounts with 2FA enabled for Administrator and Editor roles at minimum. Give existing users a short grace period (a week is reasonable) so nobody gets locked out mid-session while you roll it out.
If you manage a WooCommerce store, this is worth doing before anything else on your security checklist. See Running a WooCommerce store for the broader picture on why store admin accounts need tighter controls than a blog.
Test it on staging first
2FA plugins hook into the login flow, and a misconfigured one can lock you out of your own site. Before requiring it account-wide on a live store or business site, set it up on a staging copy first: create a clone, enable and test the full login flow there, including what happens if you cancel out of the authenticator step. See Using WordPress staging for how to spin one up. Once you've confirmed login, logout, and recovery all work as expected, roll the same setup out to production.
If you get locked out
Losing your phone or authenticator app is the main risk with TOTP. Your backup codes are the first line of recovery, each one logs you in once in place of a TOTP code. If you didn't save them, or they're exhausted, you'll need direct database or file access to disable the plugin:
- Open
File Managerfrom your service's Manage Account tiles and rename the 2FA plugin's folder insidewp-content/plugins/. This typically deactivates the plugin, which drops the 2FA requirement without touching anything else. - Log back in with just your password, fix or reconfigure 2FA, then rename the folder back (or reinstall the plugin) to re-enable it.
On most hosting accounts, nightly backups mean a recent restore point already exists if a lockout happens alongside other trouble.
When to contact support
If you're locked out of both wp-admin and your hosting File Manager, or you're not comfortable editing files directly, open a ticket from Support in the portal. It's a real person, not a bot, and they can help you get back into your files without guessing at commands on a live site.