Two Factor Verification (2FA) on WordPress
Last updated: November 25, 2024
What is the Two-Factor Verification (2FA)
Two-Factor Verification (2FA) is an enhanced security measure that requires two forms of identification before granting access to an account:
Your regular account password.
An additional code that you receive through your smartphone (ex: SMS or an authentication app).
Why is 2FA important?
Passwords can be hacked. 2FA adds an extra layer of security to ensure that even if a password is compromised, your account remains secure. By using 2FA, you protect your data and customer data from unauthorized access, significantly enhancing the overall security of your account.
What types of Two-Factor Verification do we offer?
Two-Factor Verification (2FA) Options:
Email Verification
How it works: During a login attempt, after entering your password, a confirmation code is sent to the email associated with your profile. Open the email and input the code to log in.
Notes: This is a straightforward 2FA method suitable for users who are less technologically adept. Copying and pasting the emailed code is very convenient.
Time-Based One-Time Password (TOTP) (Recommended)
How it works: Download the Google Authenticator app. Add the Sites key to the Google Authenticator app by scanning the QR code on the profile page or manually adding the key. During a login attempt, after entering your password, you will be asked for an authentication code. Input the code from the authenticator app to complete the login.
Why we recommend it: This option works offline and is the most secure.
Notes: This method works best with Google Authenticator.
- Links to download authentication Apps:
SMS
How it works: Add and confirm your phone number on the profile page. During a login attempt, after entering your password, a confirmation code is sent to the phone number associated with your profile. Open the received text message and input the code to log in.
Notes: This method is easy to use but could encounter problems if your phone is lost or your phone number is changed.
Frequently Asked Questions:
Will I still need my password after setting up 2FA?
- Yes, you will still need your password when logging in.
How often do I need to use 2FA to access the Wordpress Dashboard?
- You will need a 2FA code every time you log in to the Partner Portal.
How do I reset my 2FA if my device is lost
- To reset your 2FA, you’ll need to contact our Support team via the Contact Form. They will assist you in resetting your 2FA settings.
Troubleshooting Two-Factor Verification:
I am using the SMS option, but not receiving codes. What should I do?
Check your phone’s signal.
Ensure you have not blocked any incoming messages.
Be aware that SMS delivery may take some time.
If the issue persists, contact us via the Contact Form for further assistance. We recommend switching to the Time Based One-Time Password (TOTP) (Authenticator App) option once you are able to log back in.
Unable to set up the authenticator app?
Update your authenticator app: Ensure you have the latest version of the recommended authenticator app (app links can be found at the bottom of the article) installed on your mobile device.
Restart your device: Sometimes, simply restarting your mobile device can fix enrollment issues.
Try scanning the QR code again.
Restart the enrollment process: Log out and log back in again.
Learn about our WordPress VIP security here.