πŸ›‘οΈ
Beveiliging

Setting up two-factor authentication for web hosting

πŸ“… 8 October 2026 ✏️ 8 October 2026 ⏱ 4 min leestijd

Learn how to set up two-factor authentication (2FA) for your web hosting and Plesk account, with a step-by-step plan and tips for secure management.

Two-factor authentication (2FA) adds a second layer of security to your login: besides your password, you need a code from an app on your phone. This means that someone with only your password cannot log in to your hosting panel or email. In this article, you’ll learn how to set up 2FA in Plesk and for your email accounts, and why it’s definitely worth doing.

What is two-factor authentication

With two-factor authentication, you log in using two different pieces of evidence: something you know (your password) and something you have (a code from an authenticator app on your phone). Even if your password is leaked through a data breach or phishing email, an attacker cannot log in without that second code. This is especially important for web hosting, since your control panel grants access to websites, databases, email, and backups.

PasswordAuthenticatorapp codeAccess to Plesk

Setting up 2FA in Plesk

Plesk has built-in support for two-factor authentication via the Two-Factor Authentication extension. You can set this up under your account settings in the control panel.

1

Install an authenticator app

Install an authenticator app on your phone, such as Google Authenticator, Microsoft Authenticator, or Authy.

2

Open your account settings in Plesk

Log in to Plesk and go to your user profile, usually found in the top right via your name or avatar.

3

Activate two-factor authentication

Find the option for two-factor authentication and click to activate it. Plesk will display a QR code.

4

Scan the QR code

Scan the QR code with your authenticator app. The app will now generate a new code every thirty seconds.

5

Confirm and save recovery codes

Enter the generated code to confirm the link. Save the displayed recovery codes in a safe place, separate from your phone.

πŸ’‘ Tip: Don’t store recovery codes digitally alongside your passwords, but for example print them out and keep them in a safe place. If you lose your phone, you can still log in using these.

2FA for email and other services

In addition to your hosting panel, it’s wise to also secure your business email with two-factor authentication, especially if you use webmail or email clients that are accessible externally. Many modern email platforms support 2FA or app passwords as additional security. Check whether this option is available when setting up your email accounts; at /nl/email-hosting/ you can find more information on secure management of business email. If you use multiple domains with one provider, make sure that every account you can use to log in to domain management via /nl/domeinnamen/ is also individually secured.

If you manage multiple websites or clients, it’s smart to require 2FA for all users who have access to your Plesk environment, not just the main account. This prevents a weakly secured subaccount from making the entire environment vulnerable.

Avoiding common mistakes

A common mistake is using SMS as the only second factor. SMS codes can be intercepted through sim-swapping, so an authenticator app is safer. Also make sure you keep your recovery codes truly separate from your phone, otherwise 2FA won’t help if you lose or break your device.

Also, don’t forget to combine 2FA with a strong, unique password per account. Two-factor authentication is an extra layer, not a replacement for good password hygiene. If you’re unsure about the right settings or get stuck somewhere, consult /nl/support/ for detailed explanations of each part of your hosting environment.

Frequently Asked Questions

Does two-factor authentication work without an internet connection?

Yes, an authenticator app generates codes locally on your phone based on time, so you don’t need an internet connection to see a code.

What if I lose my phone?

Use the recovery codes you saved when setting up 2FA to regain access and link 2FA to a new device.

Can I disable 2FA if I no longer want to use it?

Yes, this can usually be done in the same account settings where you activated it, although it is not recommended for security reasons.

Is 2FA mandatory at Tandata?

Whether 2FA is mandatory depends on your settings in Plesk; you can activate it yourself and require it for multiple users.

Does 2FA also protect my website against hackers?

2FA primarily secures access to your control panel and accounts. For broader website security, updates, strong passwords, and free SSL remain important.

Conclusion

Two-factor authentication is a simple yet effective way to better secure your web hosting and email against unauthorized access. By linking an authenticator app to your Plesk account and email services, you prevent a leaked password from immediately granting access to your environment. Set it up today and keep your recovery codes safe.

View web hosting β†’

Was dit artikel nuttig?