Skip to main content

How to enable Two-Factor Authentication in cPanel

Updated yesterday

Enabling Two-Factor Authentication (2FA) add a crucial extra security layer, ensuring that even if someone steals your password, they can't access your account because they'd also need your physical device (phone, etc.) to provide a second code for approval.

Prerequisites

  • Access to cPanel

Completion of the task: 5 minutes

Expertise: beginner

How to do it?

  1. Log into your cPanel.

  2. Under Security click on Two-Factor Authentication.

  3. Click on the Set Up Two-Factor Authentication button.

  4. Now scan the QR code in step 1 with an Authenticator App on your phone like Google Authenticator by clicking on the + and selecting Scan a QR code.

  5. In step 2, enter the security code generated by your two-factor authentication app and click on the Configure Two-Factor Authentication button.

  6. Two-Factor Authentication is now configured for your cPanel account.

You can also configure Two-Factor Authentication on your Webmail account.

  1. Go to mail.yourdomain.tld:2096 (replace yourdomain.tld by your domain name).

  2. Enter your email address and password to log in.

  3. In the Webmail main page go to Two-Factor Authentication. If you logged in directly to Roundcube, in the left menu click on Webmail Home to go back in the main page.

  4. Click on the Set Up Two-Factor Authentication button.

  5. Now scan the QR code in step 1 with an Authenticator App on your phone like Google Authenticator by clicking on the + and selecting Scan a QR code.

  6. In step 2, enter the security code generated by your two-factor authentication app and click on the Configure Two-Factor Authentication button.

  7. Two-Factor Authentication is now configured for your Webmail account.

Key Benefits of Enabling 2FA:

  • Stops Password-Based Attacks: Neutralizes the threat of stolen passwords from data breaches by requiring a second verification step.

  • Protects Sensitive Data: Secures access to your account from cybercriminals.

  • Verifies Identity: Confirms you are the real user.

  • Prevents Unauthorized Access: Makes it significantly harder for hackers to get in, even if they know your password, blocking attempts like credential stuffing (using stolen passwords on other sites).

Did this answer your question?