πŸ“„
Webhosting

Setting Up Two-Factor Authentication for Your Hosting Account

πŸ“… 7 October 2026 ✏️ 7 October 2026 ⏱ 4 min leestijd

Discover how to set up two-factor authentication (2FA) for your hosting and website accounts and why it’s your best protection against hacks.

A strong password is no longer enough to keep your website and hosting account secure. With two-factor authentication (2FA), you add an extra layer of control: besides your password, you also need a code from your phone. This way, someone with a stolen password still can’t log in. In this article, you’ll learn how to set up 2FA for your Plesk account, WordPress, and other important accounts.

What exactly is two-factor authentication

With two-factor authentication, you log in using two things: something you know (your password) and something you have (your phone). After entering your password, you must enter a code generated by an authenticator app, such as Google Authenticator or Microsoft Authenticator. This code changes every thirty seconds, meaning a stolen or guessed password alone is no longer enough to log in.

The big advantage is that most hacking attempts are automated and purely focused on passwords. As soon as a second step is required that only you can perform, this type of attack immediately stalls.

Password→Authenticator→Access

Two steps instead of one: password plus code from your authenticator app.

Setting up 2FA in Plesk

In Plesk, you can activate two-factor authentication for your account, so every login is extra secure. This is especially important because Plesk gives you access to your websites, email, and databases.

1

Install an authenticator app

Install an app such as Google Authenticator on your phone before you start setting it up in Plesk.

2

Go to your account settings

Log in to Plesk and open your profile in the top right corner. Look for the option for two-factor authentication or ‘Security’.

3

Scan the QR code

Plesk displays a QR code. Scan it with your authenticator app so the app gets linked to your account.

4

Confirm with a code

Enter the six-digit code shown by the app to confirm the link and activate 2FA.

5

Save your recovery codes

Plesk provides one-time recovery codes. Store these in a safe place, separate from your phone, in case you lose your device.

πŸ’‘ Tip: Enable 2FA for every account that has access to Plesk, especially if multiple people have administrative rights. Questions about your account? Check the knowledge base for more detailed explanations per topic.

Setting up 2FA in WordPress

WordPress itself doesn’t have built-in two-factor authentication, but you can easily add this with a security plugin that supports 2FA. Install the plugin via your WordPress dashboard, activate it, and follow the instructions to link an authenticator app to your user account.

Do this at least for accounts with the ‘Administrator’ role. These are the accounts that can cause the most damage if compromised, so they deserve the strongest protection.

Which accounts deserve extra protection

Besides Plesk and WordPress, there are other places where you should consider 2FA:

Your email account is often the key to all your other accounts, since password resets go there. Make sure this account is well secured, especially if you use business email through business email hosting.

Your domain registration account also deserves attention: whoever gains access here can change DNS settings or even transfer your domain. Check domain names to see where you manage these kinds of settings.

Finally: use a unique password for every account. A password manager helps tremendously with this, so you never reuse the same password across multiple places.

Frequently Asked Questions

What if I lose my phone?

Use one of your saved recovery codes to regain access. If you didn’t save them, contact your hosting provider to have your account restored.

Is SMS verification secure enough?

SMS is better than nothing, but an authenticator app is safer because text messages can be intercepted. Use an app instead of SMS whenever possible.

Does 2FA also work for FTP accounts?

FTP itself doesn’t support 2FA, but you can best secure FTP access by only using it via SFTP and linking access to a well-secured Plesk account.

Does 2FA take extra time at every login?

It takes a few extra seconds to enter the code, but many apps and browsers remember the device for a certain period, so you don’t have to verify every single time.

Conclusion

Two-factor authentication is one of the simplest and most effective ways to protect your website and hosting account against unauthorized access. Set it up for Plesk, WordPress, and your email account, store your recovery codes safely, and use a unique password for every account. Not sure about the security of your current hosting? Check out the options for switching to Tandata.

View web hosting β†’

Was dit artikel nuttig?