Skip to content
Cloud docs

Turn on two-factor authentication

For your dashboard account, and for WordPress administrators.

Updated 20 September 20261 min readBeginner

A password alone is one leak away from an account takeover. Two-factor stops a stolen password being enough.

Your dashboard account

  1. Open Account → Security

    Choose Enable two-factor.

  2. Scan the code

    With any authenticator app: 1Password, Authy, Google Authenticator, Microsoft Authenticator.

  3. Save the recovery codes

    Store them in your password manager, not in the same place as the password. They are the only way back in if the phone is lost.

Require it for the whole team

Owners can make two-factor mandatory under Team → Policy. Members who have not enrolled are asked to do so at their next sign-in and cannot skip it.

WordPress administrators

WordPress has no built-in two-factor. Add it with a maintained plugin — the WordPress.org Two Factor plugin is a good default — and enforce it for the administrator role only, so editors are not locked out of routine work.

SMS codes

Better than nothing, worse than an app. SIM swap attacks are common enough to matter. Use an authenticator app where you have the choice.

Was this article helpful?

Related articles