How to turn on two-factor authentication for cPanel or DirectAdmin

Before you start

Install an authenticator app on your phone, such as Google Authenticator, Microsoft Authenticator or the one in your password manager.

Two-factor authentication adds a temporary code after your password. It protects the hosting account if the password is stolen.

Turn on 2FA in cPanel

  1. Sign in to cPanel.
  2. Open Security.
  3. Select Two-Factor Authentication.
  4. Select the option to set up 2FA.
  5. Scan the QR code with your authenticator app.
  6. Enter the current six-digit code.
  7. Complete the setup.

Open a private browser window and test a new login before closing your existing cPanel session.

Turn on 2FA in DirectAdmin

  1. Sign in to DirectAdmin.
  2. Open Advanced Features.
  3. Select Two-Step Authentication.
  4. Generate the secret.
  5. Scan the QR code with your authenticator app.
  6. Enter the current verification code.
  7. Enable two-step authentication.
  8. Save any emergency or scratch codes shown.

Test a new login before signing out of the original session.

Store recovery information safely

Keep recovery codes in a password manager or an encrypted offline record, somewhere separate from the phone running the authenticator. Don't email them to yourself or store them in public_html.

If a code is rejected

Check that:

  • You entered the current code.
  • The phone's date and time are set automatically.
  • You selected the correct account in the authenticator.
  • The code didn't expire while you were typing it.

Never send a current 2FA code to anyone. Webway doesn't need it for support.

If you lose the authenticator

Use a saved recovery code if you have one. Otherwise, open a support ticket. Webway will verify account ownership before resetting two-factor authentication.

For the Webway client area itself, see How to turn on two-factor authentication for my client area.

Did this answer it?