Turn on two-factor authentication
For your dashboard account, and for WordPress administrators.
A password alone is one leak away from an account takeover. Two-factor stops a stolen password being enough.
Your dashboard account
- Open Account → Security
Choose Enable two-factor.
- Scan the code
With any authenticator app: 1Password, Authy, Google Authenticator, Microsoft Authenticator.
- Save the recovery codes
Store them in your password manager, not in the same place as the password. They are the only way back in if the phone is lost.
Require it for the whole team
Owners can make two-factor mandatory under Team → Policy. Members who have not enrolled are asked to do so at their next sign-in and cannot skip it.
WordPress administrators
WordPress has no built-in two-factor. Add it with a maintained plugin — the WordPress.org Two Factor plugin is a good default — and enforce it for the administrator role only, so editors are not locked out of routine work.
Better than nothing, worse than an app. SIM swap attacks are common enough to matter. Use an authenticator app where you have the choice.
