Two-Factor Authentication (2FA) for WHM – Firstserv
What is Two-Factor Authentication (2FA)?
Two-factor authentication (2FA) adds an extra layer of security to your WHM (Web Host Manager) login by requiring a second verification step.
In addition to your password (something you know), 2FA requires a code generated by an app on a device you own (something you have), such as your phone or desktop. This means that even if your password is compromised, your account cannot be accessed without this second factor.
Why is 2FA Important?
Passwords alone can be vulnerable due to:
- Malware or compromised devices
- Use of insecure networks
- Weak or reused passwords
- Phishing attempts
By enabling 2FA, your account is protected with an additional authentication step, significantly enhancing security.
Requirements
Before setting up 2FA, you will need:
- Access to your WHM account
- A two-factor authentication app, such as:
- Authy
- Google Authenticator
- Microsoft Authenticator
Make sure the app is installed on your device before proceeding.
Setting Up 2FA in WHM
- Log in to WHM
- In the left-hand menu, navigate to:
Security Center → Two-Factor Authentication - Toggle the switch to enable the Two-Factor Authentication policy
- Click the Manage My Account tab
- Select Set Up Two-Factor Authentication
Link Your Authenticator App
- Open your 2FA app
- Add a new account by scanning the QR code or entering the key manually
- Once added, your app will begin generating One-Time Passwords (OTP codes)
- Enter a valid code into WHM
- Click Configure Two-Factor Authentication
✅ 2FA is now enabled, and your account status will show as Configured.
Disabling 2FA
If required, you can disable 2FA:
- Go to Two-Factor Authentication in WHM
- Click Remove Two-Factor Authentication
- Confirm the action
⚠️ Disabling 2FA reduces account security and is not recommended unless necessary.
If You Lose Access to Your 2FA Device
If you are unable to generate a 2FA code (for example, due to changing devices) and do not have a backup code:
- You will need to contact Firstserv support
- You will be asked to provide identity verification (ID)
- Once verified, we can assist in disabling or resetting 2FA
If you need help setting up or managing 2FA on your WHM account, the Firstserv support team is always available to assist.
