A strong password is no longer enough to keep your website and hosting account secure. With two-factor authentication (2FA), you add an extra layer of control: besides your password, you also need a code from your phone. This way, someone with a stolen password still can’t log in. In this article, you’ll learn how to set up 2FA for your Plesk account, WordPress, and other important accounts.
What exactly is two-factor authentication
With two-factor authentication, you log in using two things: something you know (your password) and something you have (your phone). After entering your password, you must enter a code generated by an authenticator app, such as Google Authenticator or Microsoft Authenticator. This code changes every thirty seconds, meaning a stolen or guessed password alone is no longer enough to log in.
The big advantage is that most hacking attempts are automated and purely focused on passwords. As soon as a second step is required that only you can perform, this type of attack immediately stalls.
Two steps instead of one: password plus code from your authenticator app.
Setting up 2FA in Plesk
In Plesk, you can activate two-factor authentication for your account, so every login is extra secure. This is especially important because Plesk gives you access to your websites, email, and databases.
Install an authenticator app
Install an app such as Google Authenticator on your phone before you start setting it up in Plesk.
Go to your account settings
Log in to Plesk and open your profile in the top right corner. Look for the option for two-factor authentication or ‘Security’.
Scan the QR code
Plesk displays a QR code. Scan it with your authenticator app so the app gets linked to your account.
Confirm with a code
Enter the six-digit code shown by the app to confirm the link and activate 2FA.
Save your recovery codes
Plesk provides one-time recovery codes. Store these in a safe place, separate from your phone, in case you lose your device.
Setting up 2FA in WordPress
WordPress itself doesn’t have built-in two-factor authentication, but you can easily add this with a security plugin that supports 2FA. Install the plugin via your WordPress dashboard, activate it, and follow the instructions to link an authenticator app to your user account.
Do this at least for accounts with the ‘Administrator’ role. These are the accounts that can cause the most damage if compromised, so they deserve the strongest protection.
Which accounts deserve extra protection
Besides Plesk and WordPress, there are other places where you should consider 2FA:
Your email account is often the key to all your other accounts, since password resets go there. Make sure this account is well secured, especially if you use business email through business email hosting.
Your domain registration account also deserves attention: whoever gains access here can change DNS settings or even transfer your domain. Check domain names to see where you manage these kinds of settings.
Finally: use a unique password for every account. A password manager helps tremendously with this, so you never reuse the same password across multiple places.
Frequently Asked Questions
What if I lose my phone?
Use one of your saved recovery codes to regain access. If you didn’t save them, contact your hosting provider to have your account restored.
Is SMS verification secure enough?
SMS is better than nothing, but an authenticator app is safer because text messages can be intercepted. Use an app instead of SMS whenever possible.
Does 2FA also work for FTP accounts?
FTP itself doesn’t support 2FA, but you can best secure FTP access by only using it via SFTP and linking access to a well-secured Plesk account.
Does 2FA take extra time at every login?
It takes a few extra seconds to enter the code, but many apps and browsers remember the device for a certain period, so you don’t have to verify every single time.
Conclusion
Two-factor authentication is one of the simplest and most effective ways to protect your website and hosting account against unauthorized access. Set it up for Plesk, WordPress, and your email account, store your recovery codes safely, and use a unique password for every account. Not sure about the security of your current hosting? Check out the options for switching to Tandata.