Enable Two-Factor Authentication For WordPress

Use this page when adding two-factor authentication to WordPress administrator accounts. Set up recovery options before enforcing 2FA so legitimate users are not locked out.

Choose A 2FA Method

WordPress supports 2FA through plugins. Many reputable security plugins include it, and some standalone 2FA plugins support authenticator apps or hardware keys.

Choose a plugin that:

Start with administrator accounts

If you do not want to require 2FA for every user, require it for administrators and anyone who can edit plugins, themes, orders, or users.

Before Enabling 2FA

  1. Confirm you have access to the administrator email address.
  2. Install an authenticator app or prepare your hardware key.
  3. Save recovery codes if the plugin provides them.
  4. Make sure at least one other trusted administrator can help if you lose access.

Enable 2FA

The exact screen varies by plugin, but the flow is usually:

  1. Sign in to WordPress as an administrator.
  2. Install and activate the 2FA or security plugin.
  3. Open the plugin's 2FA settings.
  4. Enable 2FA for your user account.
  5. Scan the QR code with an authenticator app or register your hardware key.
  6. Enter the code the app or key provides.
  7. Save the recovery codes somewhere safe.
  8. Sign out and test the login flow.

Test The Login

After enabling 2FA:

  1. Open the WordPress login page.
  2. Enter your username and password.
  3. Enter the current 2FA code or use your hardware key.
  4. Confirm you can reach the WordPress dashboard.

If the code fails, wait for the next code and try again. Authenticator app codes expire quickly.

Lost 2FA Device

If you lose the phone, key, or app used for 2FA:

Do not remove 2FA for everyone during recovery

Recover the affected account, then re-enable 2FA. Avoid turning off a useful protection globally unless that is the only way to regain access.