Setting Up 2-Factor Authentication in WordPress with the iThemes Security Plugin
Securing your administrator account is essential to safeguard your WordPress website. Using 2-Factor Authentication (2FA) is one way to increase the security of your account exponentially. Here’s how to set up 2FA using the iThemes Security plugin, which is included with all websites built by 2A Commerce:
- Accessing 2-Factor Authentication Options:
- While logging in as an admin, you might get a prompt to set up 2FA. Alternatively, you can hover over your username in the top right corner of the admin dashboard and click on Edit Profile.
- Scroll down until you find the Two-Factor Authentication Options section.
- Select an Authentication Method: There are several methods available:
- Authentication App (Recommended): To use this method, you’ll need an authenticator app on your mobile device (such as Google Authenticator). Click Enable next to this option, and then click the button to view the QR code for setup. Next, using your mobile authenticator app, scan the displayed QR code. This app will then generate unique security codes every few seconds which you’ll use to authenticate your login.
- Email Authentication: To enable this option, simply click Enable next to the email option. Once enabled, 2FA codes will be sent directly to your registered email address whenever you attempt to log in.
- Backup Authentication Codes: Lastly, consider setting up backup codes. These are useful in case you run into issues with the other methods. These one-time-use codes can get you into your account if, for instance, you can’t access your email or mobile app. Ensure that you store these backup codes in a secure location.
- If you’ve enabled more than one method, you can specify which one should be the primary method for 2FA by clicking Make Primary next to that option.
- After configuring your preferred 2FA methods, scroll down and click Update Profile.
2-Factor Authentication is now enabled for your account. This adds an additional layer of security, ensuring that even if someone discovers your password, they’ll still need the 2FA code to access your account.