{"id":30368,"date":"2025-12-17T09:14:00","date_gmt":"2025-12-17T08:14:00","guid":{"rendered":"https:\/\/www.web-systems.pl\/two-factor-authentication-wordpress-protect-admin-accounts\/"},"modified":"2026-09-30T23:05:51","modified_gmt":"2026-09-30T22:05:51","slug":"two-factor-authentication-wordpress-protect-admin-accounts","status":"publish","type":"post","link":"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/","title":{"rendered":"Two-Factor Authentication in WordPress: How to Protect Admin Accounts"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Two-factor authentication in WordPress adds a second factor to the password. It can be a code from a phone app or a hardware key. Suddenly a stolen password alone is not enough to get into the dashboard. This matters most where several people plus an agency use the admin panel and the only barrier is a password that may have leaked in a breach of a completely different service (and nobody tracks those leaks in real time). Below I explain what 2FA is, which method to choose, how to enable it step by step and who in your company should be required to use it.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#What_is_two-factor_authentication_and_why_is_a_password_not_enough\" >What is two-factor authentication and why is a password not enough?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Which_2FA_method_to_choose_in_WordPress_app_hardware_key_or_SMS\" >Which 2FA method to choose in WordPress: app, hardware key or SMS?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Does_WordPress_have_built-in_two-factor_authentication\" >Does WordPress have built-in two-factor authentication?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#How_to_enable_two-factor_authentication_in_WordPress_step_by_step\" >How to enable two-factor authentication in WordPress step by step<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Backup_codes_what_to_do_if_you_lose_your_phone\" >Backup codes: what to do if you lose your phone?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Who_in_your_company_needs_2FA_in_WordPress\" >Who in your company needs 2FA in WordPress?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Frequently_asked_questions\" >Frequently asked questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Does_two-factor_authentication_slow_down_work_in_the_dashboard\" >Does two-factor authentication slow down work in the dashboard?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#Is_SMS_2FA_better_than_no_2FA\" >Is SMS 2FA better than no 2FA?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.web-systems.pl\/en\/two-factor-authentication-wordpress-protect-admin-accounts\/#What_if_an_employee_loses_their_phone_and_has_no_backup_codes\" >What if an employee loses their phone and has no backup codes?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_two-factor_authentication_and_why_is_a_password_not_enough\"><\/span>What is two-factor authentication and why is a password not enough?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It means confirming your identity with two types of factors instead of one. <a href=\"https:\/\/developer.wordpress.org\/advanced-administration\/security\/mfa\/\" rel=\"nofollow noopener\" target=\"_blank\">The WordPress documentation on multi-factor authentication<\/a> lists three such factors: something you know (a password), something you have (a phone or a key) and something you are (biometrics, e.g. a fingerprint). The problem with passwords? The service has to store them. So even a strong, regularly changed password can leak when the server is breached.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, 2FA ties the password to a device the user carries with them. But let&#8217;s not treat it as a miracle cure. It blocks the route through a stolen password, but it won&#8217;t protect the site from an attack through a vulnerable plugin.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Which_2FA_method_to_choose_in_WordPress_app_hardware_key_or_SMS\"><\/span>Which 2FA method to choose in WordPress: app, hardware key or SMS?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In my view, an authenticator app gives the best balance between security and convenience. Hardware keys and passkeys are the strongest. And email and SMS? I would treat them as backup options, nothing more. The same WordPress documentation states plainly that SMS is not a secure communication channel.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Authenticator app (TOTP)<\/strong> - TOTP is a one-time code generated from the current time. It changes every few dozen seconds and works offline. Weak spot: the code can be typed into a fake login page.<\/li>\n<li><strong>Hardware keys and passkeys<\/strong> - you confirm the login with a physical key or the biometrics of your phone or laptop. A fake login page gets nowhere here, but both the plugin and the browser have to support it.<\/li>\n<li><strong>Email and SMS<\/strong> - easy to roll out, because you don&#8217;t need to install any app. The catch is that someone can take over the mailbox or the phone number.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Does_WordPress_have_built-in_two-factor_authentication\"><\/span>Does WordPress have built-in two-factor authentication?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. A standard installation relies on the password, and the second factor is added with a plugin. To start, I recommend the Two-Factor plugin from the official wordpress.org directory, developed by people connected with the project. Comprehensive security plugins offer similar features too, combining 2FA with a firewall and file scanning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When choosing, look at three things: which methods it supports (TOTP, keys, backup codes), how often it gets updates and whether you can enforce 2FA for selected roles. And remember that the second factor is just one piece of a bigger puzzle. I cover the whole picture in the article on <a href=\"https:\/\/www.web-systems.pl\/jak-zabezpieczyc-wordpress-przed-atakami-hakerow-bez-ryzyka\/\">protecting WordPress from hackers<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_enable_two-factor_authentication_in_WordPress_step_by_step\"><\/span>How to enable two-factor authentication in WordPress step by step<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In short: you install the plugin, then each user pairs an app or key in their profile, saves backup codes and tests the login. Step by step it looks like this:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Make a backup of the site.<\/li>\n<li>Install and activate the 2FA plugin of your choice.<\/li>\n<li>Go to <em>Users - Profile<\/em> and find the two-factor login section.<\/li>\n<li>Scan the QR code with the authenticator app on your phone.<\/li>\n<li>Enter the first generated code to confirm pairing.<\/li>\n<li>Generate backup codes and save them right away.<\/li>\n<li>Test the login in a private browser window.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Start with your own admin account. Handle the other users later. Oh, and don&#8217;t close your current session until the test in the private window succeeds. If something goes wrong, you end up locked out of your own dashboard.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Backup_codes_what_to_do_if_you_lose_your_phone\"><\/span>Backup codes: what to do if you lose your phone?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Backup codes are one-time passwords that let you into the dashboard without your phone. That&#8217;s why you save them right after enabling 2FA, not &#8220;someday&#8221;. Ideally in a password manager or on a printout kept in a safe place. Your mailbox and a file on the desktop are out. Why? Because if your computer or email is compromised, they end up in the same hands as the password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s also good to keep a second factor in reserve, e.g. a hardware key alongside the app. In your company, decide who can reset 2FA for someone else. Access to the server or hosting panel is the last resort, in case the only administrator gets locked out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Who_in_your_company_needs_2FA_in_WordPress\"><\/span>Who in your company needs 2FA in WordPress?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Everyone who can change the site. No exceptions: administrators, editors and all agency accounts. The agency and freelancers should get a separate account for each person instead of a shared login. One account used by five people can&#8217;t be sensibly combined with a second factor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While you&#8217;re at it, review the <a href=\"https:\/\/www.web-systems.pl\/role-uzytkownikow-wordpress\/\">WordPress user roles<\/a> and give everyone only the permissions they actually need. Remove inactive accounts and profiles of former collaborators (there are always some), and enforce the second factor for roles with editing rights in the plugin settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two-factor authentication in WordPress is one of several layers of protection, not a guarantee of security. If an incident happens anyway, <a href=\"https:\/\/www.web-systems.pl\/zhakowany-wordpress-pierwsze-dwie-godziny\/\">the first hours after a hack<\/a> are what counts, and for an infected site, malware removal will help.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_asked_questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1790789660500-0\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"Does_two-factor_authentication_slow_down_work_in_the_dashboard\"><\/span>Does two-factor authentication slow down work in the dashboard?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Logging in takes a few seconds longer, as long as it takes to type the code or tap the key. Many plugins let you remember a trusted device, so on your own computer you don&#8217;t enter a code every time. And the work itself after logging in? No change.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1790789660500-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"Is_SMS_2FA_better_than_no_2FA\"><\/span>Is SMS 2FA better than no 2FA?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes. A password alone is no longer enough to log in. But SMS is a weaker channel, because a phone number can be hijacked. Have a choice? Go for an authenticator app or a hardware key.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1790789660500-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"What_if_an_employee_loses_their_phone_and_has_no_backup_codes\"><\/span>What if an employee loses their phone and has no backup codes?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>The administrator resets their 2FA settings in the user profile. The employee logs in again, pairs a new device and this time saves the backup codes right away. One more thing: check whether the lost phone gave access to other company accounts.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Two-factor authentication in WordPress adds a second factor to the password. It can be a code from a phone app or a hardware key. Suddenly a stolen password alone is not enough to get into the dashboard. This matters most where several people plus an agency use the admin panel and the only barrier is [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":30355,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[828],"tags":[2323,1081,2335,2330,901,1192],"class_list":["post-30368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-2fa-x","tag-how-to","tag-login","tag-passwords","tag-security","tag-wordpress-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/posts\/30368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/comments?post=30368"}],"version-history":[{"count":1,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/posts\/30368\/revisions"}],"predecessor-version":[{"id":30378,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/posts\/30368\/revisions\/30378"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/media\/30355"}],"wp:attachment":[{"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/media?parent=30368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/categories?post=30368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.web-systems.pl\/en\/wp-json\/wp\/v2\/tags?post=30368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}