Enabling two-factor authentication

By enabling two-factor authentication, protect your user account, hosting control panel, and website admin panel against attacks and password leaks. Step-by-step tutorial and troubleshooting.

6 min Updated 9 Oct 2026

Why Two-Factor Authentication Is No Longer an Option?

Every day, thousands of user accounts are hacked simply because their password was leaked on another website and the user reused the same password across multiple services. Even the strongest password is practically worthless if it appears in a leaked database. Enabling two-factor authentication (Two-Factor Authentication, or 2FA for short) is the only way to ensure that even if someone has your password, no one else can log into your account.

In this article, you will learn, in a fully practical way, how to enable 2FA at three important levels: cloud service user accounts, hosting control panels (such as DirectAdmin or cPanel), and the WordPress admin panel. You will also become familiar with the most common mistakes and troubleshooting methods.

Different Methods of Two-Factor Authentication; Which One Should You Choose?

Before you start, you should know that 2FA does not just mean "receiving an SMS." The following methods are the most common options:

  • Authenticator Apps (Recommended): Apps such as Google Authenticator, Authy, or Microsoft Authenticator generate a 6-digit code every 30 seconds. This method works offline and does not depend on the internet or a carrier.
  • Security Keys: Such as YubiKey, which connects to your system via USB or NFC. This is the most secure option but requires purchasing hardware.
  • One-Time Backup Codes: A list of one-time codes you receive during activation and should store in a safe place. These codes are only for emergency situations.
  • SMS: The simplest method but the least secure. Your SIM card can be duplicated using social engineering tricks (SIM Swapping).

Our recommendation is to definitely use an Authenticator app and also save the backup codes. If a service only supports SMS, it is better than nothing, but know that it does not provide complete security.

Enabling 2FA in Cloud Service and Hosting User Accounts

If you use cloud services or hosting, the first step is to log into your Client Area and find the security section. Almost all reputable providers, including ServerNet, have placed the 2FA activation option in the profile settings.

General Activation Steps

  1. Log into your user account and go to the Profile or Security Settings section.
  2. Find the Two-Factor Authentication or 2FA option and click on Enable.
  3. A QR Code will be displayed on the screen. Open the Authenticator app on your phone and tap the "Add account" option.
  4. Point your phone's camera at the QR Code. The account will be added automatically.
  5. Enter the code displayed by the app on the website to confirm activation.
  6. Make sure to print the displayed Backup Codes or store them in an encrypted file.
Common Mistake: Many users close the page after scanning the QR Code without entering the verification code. In this case, 2FA is not activated, and the account may remain in a semi-active state. Always continue the process until the "final confirmation" step.

Enabling 2FA in the Hosting Control Panel (DirectAdmin and cPanel)

Your hosting control panel is the main gateway to managing your website. If someone gains access to it, they can see all your files, databases, and emails. Enabling 2FA at this level is critical.

DirectAdmin

Newer versions of DirectAdmin support 2FA by default:

  1. Log into DirectAdmin and click on your username from the top menu.
  2. Select the Two-Factor Authentication option.
  3. Click on Enable 2FA. A QR Code and a text key (Secret Key) will be displayed.
  4. Write down the text key (for times when you change your phone).
  5. Enter the 6-digit code and confirm.

cPanel

In cPanel, security plugins are usually used, but newer versions of cPanel itself also have a 2FA option:

  1. Log into cPanel and go to the Security section.
  2. Click on Two-Factor Authentication.
  3. Follow the steps to scan the QR Code and enter the code.
  4. After activation, you will receive a list of one-time codes. Be sure to download them.
Important Note: If your control panel does not have a 2FA option, ask your hosting provider to enable it. If you do not get a response, at least choose a strong and unique password for the control panel and do not use it anywhere else.

Enabling 2FA in the WordPress Admin Panel

WordPress does not have 2FA by default, but you can add it with a free and reliable plugin. Our recommendation is WP 2FA because it is simple, lightweight, and compatible with Authenticator apps.

Installing and Setting Up the WP 2FA Plugin

  1. From the WordPress dashboard, go to Plugins ← Add New.
  2. Search for WP 2FA and install and activate the plugin.
  3. From the side menu, go to WP 2FA ← Settings.
  4. In the Force 2FA for section, choose whether 2FA should be mandatory for all users or only for specific roles (e.g., administrators).
  5. Set the verification method to Time-based one-time password (TOTP).
  6. Save the settings.

Now, every user who logs in will have to enable 2FA for their account. To test, log out of your account and log back in. A page with a QR Code will be displayed. Scan it with your phone and enter the code.

Alternative Plugins

  • Google Authenticator – WordPress: Simple and popular but a bit outdated.
  • Wordfence Login Security: If you use Wordfence, you can also enable its 2FA module.
  • MiniOrange: Offers more advanced options such as login with a hardware key.

Troubleshooting Common 2FA Issues

No system is without problems. In this section, we will review the most common issues and their solutions.

The Authenticator Code Does Not Work

If the code you enter is rejected, first check the time on your phone and system. TOTP codes are generated based on time, and if your phone's clock is ahead or behind, the code will be invalid. On Android and iOS devices, enable the "automatic time setting" option.

You Have Lost or Changed Your Phone

This is where backup codes come in handy. Log in with one of the one-time codes, then disable and re-enable 2FA. If you do not have the backup codes either, you will need to recover your account through a manual verification process (usually by sending identification documents to support). This process may take a few days, so take backup codes seriously.

Logging in via FTP or SSH

2FA only applies to logging into the website and control panel, not to FTP or SSH. For these services, you should use other methods such as SSH keys or IP Whitelisting.

Common Mistake: Some users enable 2FA on a phone and later reset the phone without saving the backup codes. Result: complete account lockout. Always store backup codes in a safe place (such as a password manager) before resetting your phone.

Summary; Three Steps You Should Take Today

Enabling two-factor authentication is not difficult, but its impact on the security of your accounts is undeniable. If you have not done it yet, take these three steps today:

  1. Enable 2FA for your cloud service and hosting user account.
  2. Turn on 2FA for your hosting control panel (DirectAdmin or cPanel).
  3. Install a 2FA plugin on WordPress and make it mandatory for all administrators.

Finally, remember that 2FA is a security layer, not a replacement for a strong password. Combining a unique and long password with 2FA is the best defense against common attacks. If you encounter a problem at any step, your hosting support team (such as ServerNet) can usually guide you, but never share your password or 2FA code with anyone.

Was this page helpful?