Setting up two-factor authentication (2FA) for your website
Two-factor authentication (2FA) is one of the most effective security measures you can take to protect your website against unauthorized access. In an era where cyberattacks are becoming ever more sophisticated, two-factor authentication offers an extra security layer on top of your password. In this extensive guide we explain step by step how to set up 2FA for your website, which methods are available and why this is essential for every website owner. Also take a look at our web hosting offering.
What exactly is two-factor authentication?
Two-factor authentication, also called two-step verification or 2FA, is a security method where you have to provide two different forms of identification before you get access to your account. This means that even if someone knows your password, that person still needs a second factor to log in. The two factors typically fall into these categories:
- Something you know - your password or PIN
- Something you have - your phone, hardware token or authenticator app
- Something you are - biometric data such as fingerprint or facial recognition
By combining two of these factors, you make it exponentially harder for malicious actors to get access to your website. Even in the event of a data breach where passwords leak, your account stays protected with two-factor authentication.
Why two-factor authentication is indispensable
Statistics show that more than 80% of all data breaches are related to weak or stolen passwords. Two-factor authentication blocks up to 99.9% of automated attacks on accounts. Here are the most important reasons why you should activate 2FA:
Protection against brute-force attacks
In a brute-force attack an attacker systematically tries all possible password combinations. With two-factor authentication the password alone is not enough, which makes these attacks useless. Also read our guide on securing your website for more protection strategies.
Protection against phishing
Even if you accidentally enter your password on a fake website, the attacker cannot log in without the second factor. This makes 2FA a powerful weapon against phishing attacks that are becoming ever more convincing.
Compliance and trust
Many regulations such as the GDPR require appropriate security measures. Two-factor authentication is a recognized best practice that shows you take the security of user data seriously. This increases the trust of your visitors and customers.
Methods for two-factor authentication compared
There are various methods available for implementing two-factor authentication on your website. Each method has its own advantages and disadvantages. Below we compare the most common options:
| Method | Security | Ease of use | Cost | Suitable for |
|---|---|---|---|---|
| Authenticator app (TOTP) | High | Good | Free | All websites |
| SMS codes | Medium | Very good | Per SMS | Low-threshold use |
| Hardware token (U2F/FIDO2) | Very high | Good | One-time purchase | High security |
| Email verification | Low-medium | Very good | Free | Basic security |
| Push notifications | High | Excellent | Variable | Mobile users |
| Biometric (WebAuthn) | Very high | Excellent | Free | Modern devices |
Setting up two-factor authentication with an authenticator app
The most recommended method for two-factor authentication is using an authenticator app. These apps generate a unique code every 30 seconds that you enter alongside your password. Popular authenticator apps are Google Authenticator, Microsoft Authenticator and Authy.
Step 1: Choose an authenticator app
Download an authenticator app on your smartphone. We recommend Authy because of its cloud backup function, which means you do not lose your codes if your phone breaks. Other good options are:
- Google Authenticator - simple and reliable, no account needed
- Microsoft Authenticator - ideal if you already use Microsoft products
- Authy - supports cloud backup and multiple devices
- 1Password - integrated into the password manager
Step 2: Activate 2FA in your website dashboard
Log in to the admin panel of your website and navigate to the security settings. With most CMS systems and hosting panels you find the option for two-factor authentication under "Security" or "Account settings". Do you use DirectAdmin as your hosting panel? Then you find the 2FA option under your account settings.
Step 3: Scan the QR code
Your website shows a QR code that you scan with your authenticator app. This exchanges a shared secret that forms the basis for generating the codes. Also keep the recovery codes that are shown in a safe place.
Step 4: Verify and activate
Enter the 6-digit code that your authenticator app shows to confirm that everything is set up correctly. After verification, two-factor authentication is active on your account.
Setting up two-factor authentication for WordPress
WordPress is the most used CMS in the world and therefore a popular target for hackers. Fortunately, setting up two-factor authentication on your WordPress site is easy with the right plugins. Also take a look at our guide on WordPress maintenance for more security tips.
Recommended WordPress 2FA plugins
There are various reliable plugins available for two-factor authentication on WordPress:
- Wordfence Security - complete security plugin with built-in 2FA
- WP 2FA - specifically focused on two-factor authentication with extensive options
- Google Authenticator by miniOrange - supports multiple 2FA methods
- Two Factor Authentication - lightweight plugin for basic 2FA
- iThemes Security - all-in-one security plugin with 2FA support
Installation step by step
Follow these steps to set up two-factor authentication on your WordPress website:
- Go to Plugins > Add New Plugin in your WordPress dashboard
- Search for "WP 2FA" or another 2FA plugin of your choice
- Click Install Now and then Activate
- The setup wizard starts automatically - follow the steps
- Choose your desired 2FA method (authenticator app recommended)
- Scan the QR code with your authenticator app
- Enter the verification code and save the recovery codes
- Optional: require 2FA for all user roles
After installation you can set which user roles are required to use two-factor authentication. For maximum security we recommend requiring this at least for administrators and editors.
Two-factor authentication for DirectAdmin and hosting panels
In addition to your website itself, it is also important to set up two-factor authentication on your hosting panel. If you use DirectAdmin, you can activate 2FA as follows:
- Log in to DirectAdmin
- Go to Account Manager > Two-Step Authentication
- Click Enable Two-Step Authentication
- Scan the QR code with your authenticator app
- Enter the verification code for confirmation
- Keep the emergency codes in a safe location
Do not forget to also set up 2FA for your FTP accounts and database access if your hosting provider supports this.
SMS-based two-factor authentication
Although SMS-based 2FA is better than no 2FA, it is no longer considered the safest option. This is due to vulnerabilities such as SIM swapping, where an attacker takes over your phone number. Still, SMS 2FA can be useful as an additional security layer for less critical accounts.
Advantages of SMS 2FA
- Very user-friendly - anyone can receive SMS
- No extra app needed
- Works on any type of phone (even without a smartphone)
Disadvantages of SMS 2FA
- Vulnerable to SIM swapping attacks
- SMS messages can be intercepted
- Dependent on mobile network coverage
- Costs per SMS sent
Hardware tokens for maximum security
For the highest level of security you can use hardware tokens such as YubiKey or SoloKeys. These physical devices support the FIDO2/WebAuthn protocol and are virtually impossible to hack remotely. They are especially suitable for companies with high security requirements.
Hardware tokens work by performing a cryptographic handshake with the website. You only have to connect the token via USB or NFC and tap on it to confirm your identity. No codes are sent that could be intercepted.
Popular hardware tokens
| Token | Price (from) | Protocols | Connection |
|---|---|---|---|
| YubiKey 5 NFC | ~€50 | FIDO2, U2F, TOTP, PIV | USB-A, NFC |
| YubiKey 5C | ~€55 | FIDO2, U2F, TOTP, PIV | USB-C |
| SoloKeys Solo 2 | ~€30 | FIDO2, U2F | USB-A, NFC |
| Thetis FIDO2 | ~€25 | FIDO2, U2F | USB-A |
| Google Titan Key | ~€35 | FIDO2, U2F | USB-A/C, NFC, BLE |
Best practices for two-factor authentication
Setting up two-factor authentication is only the first step. To benefit maximally from this security measure, follow these best practices:
Store recovery codes safely
When setting up 2FA you get recovery codes with which you can log in if you lose your second factor. Print these codes and keep them in a safe physical location, or store them in an encrypted password manager. Never store them unencrypted on your computer.
Use a backup method
Always set up a second 2FA method as a backup. If your primary method is an authenticator app, add a hardware token as well, for example. That way you prevent being locked out if one method is unavailable.
Require 2FA for all administrators
On a website with multiple users you must require two-factor authentication for all accounts with administrator rights. A chain is only as strong as its weakest link, and an unprotected administrator account is a big security risk.
Combine 2FA with strong passwords
Two-factor authentication does not replace a strong password. Always use unique passwords of at least 12 characters with a mix of letters, numbers and special characters. A password manager helps with this. Also see how an SSL certificate further secures your website.
Troubleshooting two-factor authentication
Sometimes problems can occur with 2FA. Here are the most common problems and solutions:
Codes do not work
If your authenticator codes are not accepted, check whether the time on your phone is set correctly. TOTP codes are time-bound and even a difference of 30 seconds can cause problems. Set the time to automatic in your phone settings.
Phone lost or stolen
Use your saved recovery codes to log in. If you use Authy with cloud backup, you can install the app on a new device and restore your codes. Otherwise contact your hosting provider for a manual reset.
Disabling 2FA as an emergency measure
If you no longer have access to your second factor and have no recovery codes, there are still options. With WordPress you can deactivate the 2FA plugin via FTP by renaming the plugin folder. With hosting panels you have to contact your provider for identity verification and reset.
Implementing two-factor authentication for visitors
In addition to securing your own administrator accounts, you can also offer or require two-factor authentication for the users of your website. This is especially relevant for online stores, member portals and other sites where users store personal data.
Implementation considerations
- Make 2FA optional for regular users - requiring it can lead to drop-off
- Offer multiple methods - not everyone has a smartphone
- Communicate the benefits - explain why 2FA is important
- Provide good documentation - make setting it up as simple as possible
- Offer support for problems - have a clear recovery process
The future of two-factor authentication
The technology behind two-factor authentication is developing rapidly. Passkeys, based on the FIDO2/WebAuthn protocol, are becoming ever more widely supported and promise a future in which passwords may disappear entirely. This technology uses biometric verification or a PIN on your device as a replacement for the traditional password plus second factor.
Big tech companies such as Apple, Google and Microsoft already support passkeys in their browsers and operating systems. For website owners this means that in addition to traditional 2FA you also have to be prepared for these new standards.
Checklist: implementing two-factor authentication
Use this checklist to make sure you do not overlook anything when implementing two-factor authentication on your website:
- Inventory all accounts that have access to your website
- Choose a primary 2FA method (authenticator app recommended)
- Install and configure the required plugin or module
- Activate 2FA for your own administrator account first
- Test the login process thoroughly with the new 2FA
- Store recovery codes safely (physically and/or encrypted)
- Set up a backup 2FA method
- Require 2FA for all users with administrator rights
- Document the recovery process in case of 2FA loss
- Inform all users about the new security measure
- Regularly check whether 2FA still functions correctly
Two-factor authentication is no longer a luxury but a necessity for every website. By setting up 2FA today, you protect not only yourself but also the data of your visitors. Start with your most important accounts and gradually expand to all systems you use. The small extra effort when logging in is far outweighed by the enormous improvement in security that two-factor authentication offers.
Comparing two-factor authentication methods
Not all forms of two-factor authentication offer the same level of security. Choosing the right method depends on your specific situation, the risk profile of your website and the ease of use for your visitors. Below we compare the most used 2FA methods based on security, cost and practical usability.
| 2FA method | Security level | Cost | Ease of use | Suitable for |
|---|---|---|---|---|
| SMS verification | Basic | Low | Very simple | Small websites, blogs |
| Authenticator app (TOTP) | High | Free | Simple | Most websites |
| Hardware security key (U2F) | Very high | EUR 20-60 per key | Medium | Sensitive data, e-commerce |
| Push notifications | High | Variable | Very simple | Business environments |
| Biometric (WebAuthn) | Very high | Free | Very simple | Modern browsers |
SMS verification is the best-known form, but also the most vulnerable. SIM swapping attacks make it possible for criminals to take over your phone number. Authenticator apps such as Google Authenticator or Authy generate time-bound codes that change every 30 seconds and work fully offline. This makes them a lot safer than SMS.
Hardware security keys as the gold standard
For maximum protection, hardware security keys such as YubiKey or SoloKey are the best option. These physical devices use the FIDO2/WebAuthn protocol and are virtually impossible to phish. The key has to be physically present when logging in, which rules out remote attacks. More and more hosting providers and platforms support this method.
Common mistakes when implementing two-factor authentication
When setting up two-factor authentication on your website, things regularly go wrong. These mistakes can undermine security or lock out users. Know the pitfalls to avoid them.
- Not keeping backup codes - If you lose your phone without backup codes, you get locked out of your own account. Always keep recovery codes in a safe, offline location.
- Setting up 2FA only for admins - All users with access to sensitive information should use 2FA, not just administrators.
- Not testing the recovery procedure - Test the recovery process before you need it. Many websites offer a cumbersome procedure that does not work in practice.
- Relying only on SMS - SMS is better than nothing, but considerably weaker than app-based or hardware solutions.
- Not training users - Without explanation users drop off. Make clear instructions and offer support with setup.
A solid implementation of two-factor authentication also requires a good password policy. Combine 2FA with strong, unique passwords and a website firewall for optimal protection. Do not forget to secure your VPS if you host your website yourself.
Two-factor authentication for WordPress and online stores
For WordPress websites there are various plugins available that add two-factor authentication. The most popular options are Wordfence, WP 2FA and Two Factor Authentication by miniOrange. Each offers unique advantages:
- Wordfence - Combines 2FA with a complete firewall and malware scanner. Ideal if you look for an all-in-one solution for WordPress security.
- WP 2FA - Lightweight plugin specifically for two-factor authentication. Supports TOTP apps and email as second factor.
- miniOrange - Offers the most 2FA methods, including phone verification, push notifications and security questions.
For WooCommerce online stores, two-factor authentication is extra important because of customer data and payment information. Implement 2FA at least for all administrators and employees with access to the dashboard. Also consider offering customers the option to secure their account extra with 2FA, especially if they store payment details. Good hosting for online stores offers server-level security measures as an extra protection layer.
The future of two-factor authentication: passkeys and passwordless
The future of two-factor authentication lies in passwordless login. Passkeys, developed by the FIDO Alliance and supported by Apple, Google and Microsoft, fully replace traditional passwords. Instead of a password plus second factor you use a single cryptographic key that is stored on your device and secured with biometrics or a PIN.
Passkeys offer various advantages over traditional 2FA. They are phishing-resistant because the key is bound to the specific domain. There are no codes to remember or type over, which improves the user experience. In addition they synchronize securely between your devices via iCloud Keychain, Google Password Manager or Windows Hello. For website administrators this means fewer password reset requests, higher conversion rates on login pages and better security without extra friction for users. The transition to passkeys has already begun and will accelerate in the coming years as browser support increases and users become familiar with the technology.
Sources and references
- WooCommerce - Official documentation (woocommerce.com)
- Wordfence - WordPress Security Report (wordfence.com)
- Dutch Data Protection Authority - GDPR information (autoriteitpersoonsgegevens.nl)