Two-factor authentication in WordPress adds a second factor to the password. It can be a code from a phone app or a hardware key. Suddenly a stolen password alone is not enough to get into the dashboard. This matters most where several people plus an agency use the admin panel and the only barrier is a password that may have leaked in a breach of a completely different service (and nobody tracks those leaks in real time). Below I explain what 2FA is, which method to choose, how to enable it step by step and who in your company should be required to use it.
Table of contents
What is two-factor authentication and why is a password not enough?
It means confirming your identity with two types of factors instead of one. The WordPress documentation on multi-factor authentication lists three such factors: something you know (a password), something you have (a phone or a key) and something you are (biometrics, e.g. a fingerprint). The problem with passwords? The service has to store them. So even a strong, regularly changed password can leak when the server is breached.
In practice, 2FA ties the password to a device the user carries with them. But let’s not treat it as a miracle cure. It blocks the route through a stolen password, but it won’t protect the site from an attack through a vulnerable plugin.
Which 2FA method to choose in WordPress: app, hardware key or SMS?
In my view, an authenticator app gives the best balance between security and convenience. Hardware keys and passkeys are the strongest. And email and SMS? I would treat them as backup options, nothing more. The same WordPress documentation states plainly that SMS is not a secure communication channel.
- Authenticator app (TOTP) - TOTP is a one-time code generated from the current time. It changes every few dozen seconds and works offline. Weak spot: the code can be typed into a fake login page.
- Hardware keys and passkeys - you confirm the login with a physical key or the biometrics of your phone or laptop. A fake login page gets nowhere here, but both the plugin and the browser have to support it.
- Email and SMS - easy to roll out, because you don’t need to install any app. The catch is that someone can take over the mailbox or the phone number.
Does WordPress have built-in two-factor authentication?
No. A standard installation relies on the password, and the second factor is added with a plugin. To start, I recommend the Two-Factor plugin from the official wordpress.org directory, developed by people connected with the project. Comprehensive security plugins offer similar features too, combining 2FA with a firewall and file scanning.
When choosing, look at three things: which methods it supports (TOTP, keys, backup codes), how often it gets updates and whether you can enforce 2FA for selected roles. And remember that the second factor is just one piece of a bigger puzzle. I cover the whole picture in the article on protecting WordPress from hackers.
How to enable two-factor authentication in WordPress step by step
In short: you install the plugin, then each user pairs an app or key in their profile, saves backup codes and tests the login. Step by step it looks like this:
- Make a backup of the site.
- Install and activate the 2FA plugin of your choice.
- Go to Users - Profile and find the two-factor login section.
- Scan the QR code with the authenticator app on your phone.
- Enter the first generated code to confirm pairing.
- Generate backup codes and save them right away.
- Test the login in a private browser window.
Start with your own admin account. Handle the other users later. Oh, and don’t close your current session until the test in the private window succeeds. If something goes wrong, you end up locked out of your own dashboard.
Backup codes: what to do if you lose your phone?
Backup codes are one-time passwords that let you into the dashboard without your phone. That’s why you save them right after enabling 2FA, not “someday”. Ideally in a password manager or on a printout kept in a safe place. Your mailbox and a file on the desktop are out. Why? Because if your computer or email is compromised, they end up in the same hands as the password.
It’s also good to keep a second factor in reserve, e.g. a hardware key alongside the app. In your company, decide who can reset 2FA for someone else. Access to the server or hosting panel is the last resort, in case the only administrator gets locked out.
Who in your company needs 2FA in WordPress?
Everyone who can change the site. No exceptions: administrators, editors and all agency accounts. The agency and freelancers should get a separate account for each person instead of a shared login. One account used by five people can’t be sensibly combined with a second factor.
While you’re at it, review the WordPress user roles and give everyone only the permissions they actually need. Remove inactive accounts and profiles of former collaborators (there are always some), and enforce the second factor for roles with editing rights in the plugin settings.
Two-factor authentication in WordPress is one of several layers of protection, not a guarantee of security. If an incident happens anyway, the first hours after a hack are what counts, and for an infected site, malware removal will help.
Frequently asked questions
Does two-factor authentication slow down work in the dashboard?
Logging in takes a few seconds longer, as long as it takes to type the code or tap the key. Many plugins let you remember a trusted device, so on your own computer you don’t enter a code every time. And the work itself after logging in? No change.
Is SMS 2FA better than no 2FA?
Yes. A password alone is no longer enough to log in. But SMS is a weaker channel, because a phone number can be hijacked. Have a choice? Go for an authenticator app or a hardware key.
What if an employee loses their phone and has no backup codes?
The administrator resets their 2FA settings in the user profile. The employee logs in again, pairs a new device and this time saves the backup codes right away. One more thing: check whether the lost phone gave access to other company accounts.








