Set up Two-Factor Authentication (2FA) in DirectAdmin
Two-Factor Authentication (2FA) adds an extra security layer to your DirectAdmin account. Besides your password, you also need a code from your phone to log in. This makes it virtually impossible for hackers to gain access, even if they know your password.
Why use 2FA?
Your DirectAdmin account contains sensitive data:
- Email accounts: Access to all your email
- Databases: Your website data
- Files: All your website files
- FTP credentials: Upload permissions
If someone gains access to your DirectAdmin, they can:
- Modify or delete your website
- Send spam through your email
- Install malware
- Steal your data
2FA prevents this, even with a leaked password.
What do you need?
- A smartphone (Android or iPhone)
- An authenticator app:
- Google Authenticator (recommended)
- Microsoft Authenticator
- Authy
- 1Password (if you already use it)
Setting up 2FA in DirectAdmin
Step 1: Download an authenticator app
Download one of the following apps on your phone:
Android:
- Open the Google Play Store
- Search for "Google Authenticator"
- Install the app by Google LLC
iPhone:
- Open the App Store
- Search for "Google Authenticator"
- Install the app
Step 2: Go to security settings
- Log in to DirectAdmin
- Click your username in the top right
- Select "Two-Step Authentication or "Security
- Or go directly to: Account Manager → Two-Step Authentication
Step 3: Activate 2FA
- Click "Enable Two-Step Authentication
- A QR code appears on your screen
- Save the backup codes! (very important)
Step 4: Scan the QR code
- Open the authenticator app on your phone
- Tap the plus icon (+)
- Choose "Scan QR code
- Point your camera at the QR code in DirectAdmin
- The app now shows a 6-digit code
Step 5: Verify the code
- Enter the 6-digit code in DirectAdmin
- Click "Verify
- 2FA is now active!
Saving backup codes
This is crucial! If you lose your phone, you cannot log in without backup codes.
- DirectAdmin shows backup codes after activation
- Write these on paper and store them safely
- Or save them in a password manager
- DO NOT save them on your phone
Each backup code works once. Use them only in emergencies.
Logging in with 2FA
After activation, logging in works as follows:
- Go to the DirectAdmin login page
- Enter your username and password
- Click "Login"
- You will be asked for a verification code
- Open the authenticator app
- Enter the displayed code (refreshes every 30 seconds)
- Click "Verify"
Tip: The code changes every 30 seconds. Don't wait too long to enter it.
Disabling 2FA
If you want to disable 2FA:
- Log in to DirectAdmin (with 2FA code)
- Go to Two-Step Authentication
- Click "Disable Two-Step Authentication
- Confirm with your password
- 2FA is disabled
Note: This makes your account less secure. Only do this if really necessary.
Troubleshooting
Code doesn't work
- Check if the time on your phone is correct
- Wait for a new code to appear
- Make sure you select the correct account in the app
Phone lost or broken
- Use a backup code to log in
- Temporarily disable 2FA
- Set up 2FA again with your new phone
No more backup codes
Contact support. We can reset 2FA after verifying your identity.
New phone
- Log in with your old phone (or backup code)
- Disable 2FA
- Set up 2FA again with your new phone
- Save the new backup codes
Best practices
- Always use 2FA - The extra second when logging in is more than worth it
- Store backup codes safely - On paper, in a safe
- Update your app - Keep the authenticator app up-to-date
- Check regularly - Test that you can still log in
Questions?
Having problems with 2FA? Contact support. We're happy to help.
0 van 0 vonden dit nuttig