Why Two-Factor Authentication Is No Longer an Option?
Every day, thousands of user accounts are hacked simply because their password was leaked on another website and the user reused the same password across multiple services. Even the strongest password is practically worthless if it appears in a leaked database. Enabling two-factor authentication (Two-Factor Authentication, or 2FA for short) is the only way to ensure that even if someone has your password, no one else can log into your account.
In this article, you will learn, in a fully practical way, how to enable 2FA at three important levels: cloud service user accounts, hosting control panels (such as DirectAdmin or cPanel), and the WordPress admin panel. You will also become familiar with the most common mistakes and troubleshooting methods.
Different Methods of Two-Factor Authentication; Which One Should You Choose?
Before you start, you should know that 2FA does not just mean "receiving an SMS." The following methods are the most common options:
- Authenticator Apps (Recommended): Apps such as Google Authenticator, Authy, or Microsoft Authenticator generate a 6-digit code every 30 seconds. This method works offline and does not depend on the internet or a carrier.
- Security Keys: Such as YubiKey, which connects to your system via USB or NFC. This is the most secure option but requires purchasing hardware.
- One-Time Backup Codes: A list of one-time codes you receive during activation and should store in a safe place. These codes are only for emergency situations.
- SMS: The simplest method but the least secure. Your SIM card can be duplicated using social engineering tricks (SIM Swapping).
Our recommendation is to definitely use an Authenticator app and also save the backup codes. If a service only supports SMS, it is better than nothing, but know that it does not provide complete security.
Enabling 2FA in Cloud Service and Hosting User Accounts
If you use cloud services or hosting, the first step is to log into your Client Area and find the security section. Almost all reputable providers, including ServerNet, have placed the 2FA activation option in the profile settings.
General Activation Steps
- Log into your user account and go to the
ProfileorSecurity Settingssection. - Find the
Two-Factor Authenticationor2FAoption and click onEnable. - A QR Code will be displayed on the screen. Open the Authenticator app on your phone and tap the "Add account" option.
- Point your phone's camera at the QR Code. The account will be added automatically.
- Enter the code displayed by the app on the website to confirm activation.
- Make sure to print the displayed Backup Codes or store them in an encrypted file.
Enabling 2FA in the Hosting Control Panel (DirectAdmin and cPanel)
Your hosting control panel is the main gateway to managing your website. If someone gains access to it, they can see all your files, databases, and emails. Enabling 2FA at this level is critical.
DirectAdmin
Newer versions of DirectAdmin support 2FA by default:
- Log into DirectAdmin and click on your username from the top menu.
- Select the
Two-Factor Authenticationoption. - Click on
Enable 2FA. A QR Code and a text key (Secret Key) will be displayed. - Write down the text key (for times when you change your phone).
- Enter the 6-digit code and confirm.
cPanel
In cPanel, security plugins are usually used, but newer versions of cPanel itself also have a 2FA option:
- Log into cPanel and go to the
Securitysection. - Click on
Two-Factor Authentication. - Follow the steps to scan the QR Code and enter the code.
- After activation, you will receive a list of one-time codes. Be sure to download them.
Enabling 2FA in the WordPress Admin Panel
WordPress does not have 2FA by default, but you can add it with a free and reliable plugin. Our recommendation is WP 2FA because it is simple, lightweight, and compatible with Authenticator apps.
Installing and Setting Up the WP 2FA Plugin
- From the WordPress dashboard, go to
Plugins ← Add New. - Search for
WP 2FAand install and activate the plugin. - From the side menu, go to
WP 2FA ← Settings. - In the
Force 2FA forsection, choose whether 2FA should be mandatory for all users or only for specific roles (e.g., administrators). - Set the verification method to
Time-based one-time password (TOTP). - Save the settings.
Now, every user who logs in will have to enable 2FA for their account. To test, log out of your account and log back in. A page with a QR Code will be displayed. Scan it with your phone and enter the code.
Alternative Plugins
- Google Authenticator – WordPress: Simple and popular but a bit outdated.
- Wordfence Login Security: If you use Wordfence, you can also enable its 2FA module.
- MiniOrange: Offers more advanced options such as login with a hardware key.
Troubleshooting Common 2FA Issues
No system is without problems. In this section, we will review the most common issues and their solutions.
The Authenticator Code Does Not Work
If the code you enter is rejected, first check the time on your phone and system. TOTP codes are generated based on time, and if your phone's clock is ahead or behind, the code will be invalid. On Android and iOS devices, enable the "automatic time setting" option.
You Have Lost or Changed Your Phone
This is where backup codes come in handy. Log in with one of the one-time codes, then disable and re-enable 2FA. If you do not have the backup codes either, you will need to recover your account through a manual verification process (usually by sending identification documents to support). This process may take a few days, so take backup codes seriously.
Logging in via FTP or SSH
2FA only applies to logging into the website and control panel, not to FTP or SSH. For these services, you should use other methods such as SSH keys or IP Whitelisting.
Summary; Three Steps You Should Take Today
Enabling two-factor authentication is not difficult, but its impact on the security of your accounts is undeniable. If you have not done it yet, take these three steps today:
- Enable 2FA for your cloud service and hosting user account.
- Turn on 2FA for your hosting control panel (DirectAdmin or cPanel).
- Install a 2FA plugin on WordPress and make it mandatory for all administrators.
Finally, remember that 2FA is a security layer, not a replacement for a strong password. Combining a unique and long password with 2FA is the best defense against common attacks. If you encounter a problem at any step, your hosting support team (such as ServerNet) can usually guide you, but never share your password or 2FA code with anyone.