Have questions about paid ads, campaign optimisation, or platform features? Browse our knowledge base for step-by-step guides, FAQs, and expert insights to help you succeed.
Turning On Two-Factor Authentication for Your Website
On This Page
A password can be stolen without you ever noticing. It leaks in a breach at some unrelated company, it gets guessed because it was reused, or someone is simply patient. Two-factor authentication means a stolen password on its own is not enough to get into your website, because logging in also needs a code from your phone. It takes about five minutes to set up, once, and it is the single most effective thing you can do to protect your site. If you have admin access to your website, this guide is for you.
This is all done through Defender Pro, the security plugin we install and look after on every website we build, so it is already sitting on your site and there is nothing to buy, download or install. If you work through the steps below and cannot find the settings described, it most likely means Defender Pro is not installed or not activated on your site. Email us and we will sort it out rather than you hunting for something that is not there.
What this does not do. It does not change your password. It does not affect your public website, your customers, or anyone filling in your forms. It only applies when you or a colleague signs in to the back of the site. And it will not lock you out, provided you do the backup codes step below, which is why that step has a warning next to it rather than being buried in a list.
Before you start
- Have your phone with you and sit down somewhere for five minutes. Do not start this on your way out the door.
- You will install a free authenticator app if you do not already have one. Google Authenticator, Microsoft Authenticator and Authy are all free, and any of them works. If your workplace already uses one for something else, use that.
- You will need somewhere safe to keep a short list of backup codes. A password manager is ideal. A note in your email inbox is not.
Which method to choose
Your site offers four options and they are not equally good. This is the part worth reading properly, because the default choice most people make is the weakest one.
| Option | What it is | Our view |
|---|---|---|
| TOTP Authenticator App | A free app on your phone showing a six digit code that changes every 30 seconds. | ⭐ Choose this. Works with no signal, nothing to intercept, takes seconds. |
| Web Authentication | Your fingerprint or face on a device you already unlock that way, or a physical security key. | Excellent, and the most convenient. Tied to that one device, so pair it with the app. |
| Fallback Email | A code emailed to you when you log in. | ⚠️ The weakest option. Anyone who gets into your email gets into your website. Keep it as a spare, not your main method. |
| Backup Codes | A short list of one-use codes you save now and use if you lose your phone. | Not really a method, a safety net. Everybody should have these. |
Our recommendation, in one line: set up the authenticator app, download your backup codes, and if you want fallback email as well then add it as a spare rather than as your only route in.
Setting it up
- Log in to your website and go to Users, then Profile. On some sites this is shown as Your Profile, and you can also reach it from your own name in the top right corner.
- Scroll down to the Two-Factor Authentication section. It is usually well down the page, past the colour scheme and contact details.
- Choose TOTP Authenticator App and enable it. The site shows you a QR code.
- Open your authenticator app, choose to add an account, and point your phone’s camera at the QR code on screen. The app immediately starts showing a six digit code for your website.
- Type that six digit code back into the box on your website to prove it worked, and save. If it is rejected, it has probably just rolled over to a new code. Wait for a fresh one and try again.
- Now do the backup codes. See the warning below. Do not close the page first.
Download your backup codes before you leave that page. Choose Backup Codes and use Download Codes. These are your way back in if your phone is lost, stolen, broken or replaced. Without them, getting you back into your own website means someone with server access rebuilding your login by hand, and that is a support ticket and a wait rather than a two minute fix. Keep them in a password manager or printed somewhere sensible. Do not keep them only on the phone that is running the authenticator app, and do not email them to yourself, because both of those defeat the point.
What logging in looks like from now on
You enter your username and password as usual, and then a second screen asks for the six digit code. Open your authenticator app, read the code, type it in. That is the whole difference. It adds a few seconds and it means that someone who has somehow obtained your password still cannot get in.
Never photograph, forward or share the QR code or the setup key. That image is not a picture of a setting, it is the secret. Anyone who has it can generate your codes forever, from anywhere, and you would have no way of knowing. Do not send it to a colleague, do not put it in a shared document, and do not send it to us. If you think somebody else has seen it, tell us and we will reset it.
When you get a new phone
This is the moment people get caught out, and it is entirely avoidable.
- Planned upgrade. Set the authenticator up on the new phone before you wipe or trade in the old one. Most authenticator apps have a transfer or export feature that moves your accounts across in one go.
- Lost, stolen or broken phone. Use one of your backup codes to log in, then set the authenticator up again on the replacement. Each backup code works once.
- No phone and no backup codes. Contact us. We can get you back in, but it needs someone with server access and it is not instant, so it is worth the two minutes of saving those codes.
If you are the person switching it on for everybody
The setting lives in Defender, then 2FA. You choose which user roles it applies to, and separately whether it is required or merely available.
Require it, do not merely offer it. Across the sites we look after the pattern is stark. Where 2FA is switched on but optional, close to nobody sets it up, even on sites with a dozen administrators. Where it is required for administrators, everybody has it. Leaving it optional feels considerate and achieves almost nothing.
Three things worth doing when you turn it on:
- Tell people first. Being redirected to a setup screen with no warning, mid task, is how you generate a morning of support questions. Send this guide round a few days ahead.
- Start with administrators. They are the accounts worth attacking. You can widen it later.
- Write a custom message. There is a field for the text people see when they are asked to set it up. One sentence saying who to ask for help is worth a lot.
Common questions
- Do I need it if I have a strong password? Yes. Strength is not the issue. Most passwords are stolen or leaked rather than guessed, and a leaked strong password is just as useful to an attacker as a weak one.
- Will it ask me every single time? Every time you sign in, yes. It will not interrupt you while you are already working.
- Does this cost anything? No. The feature is part of the security plugin already on your site, and the authenticator apps are free.
- I have several sites with you. Each one is separate. Your app can hold them all, so name them clearly when you add them.
What to send us if something goes wrong
- Which website, and the username or email address you are signing in with.
- Which method you set up, and whether you still have your backup codes.
- The exact wording of any error, screenshotted in full.
Never send us a code, a backup code, your password, or the QR image. We will never ask for any of them, and anyone who does is not us.
Related
Still haven’t found what you’re looking for?
Let us know and we’ll do our best to help out!