Two-Factor Authentication (2FA) for cPanel – Firstserv
What is Two-Factor Authentication (2FA)?
Two-factor authentication (2FA) adds an extra layer of security to your cPanel account by requiring a second verification step when you log in.
In addition to your password (something you know), 2FA requires a code generated by an app on a device you own (something you have), such as your mobile phone or desktop. This ensures that even if your password is compromised, your account cannot be accessed without the second factor.
Why is 2FA Important?
Passwords can be compromised for several reasons, including:
- Lost or stolen devices
- Malware or phishing attacks
- Use of insecure networks
- Reusing the same password across multiple services
By enabling 2FA, your account remains protected even if your password is exposed.
Requirements
Before setting up 2FA, you will need:
- Access to your cPanel account
- A two-factor authentication app, such as:
- Authy
- Google Authenticator
- Microsoft Authenticator
Make sure the app is installed on your device before starting.
Setting Up 2FA in cPanel
- Log in to cPanel
- Navigate to the Security section
- Click Two-Factor Authentication
- Click Set Up Two-Factor Authentication
Step 1: Add Your Account to the Authenticator App
- Open your 2FA app
- Add a new account by scanning the QR code or entering the key manually
- Once added, the app will begin generating one-time passcodes (OTP)
Step 2: Verify and Activate
- Enter a valid code from your authenticator app
- Click Configure Two-Factor Authentication
✅ You will see a confirmation message once 2FA has been successfully enabled.
Managing 2FA
After setup, returning to the Two-Factor Authentication page will allow you to:
- Reconfigure your 2FA settings
- Remove 2FA if necessary
Disabling 2FA
To remove 2FA:
- Go to Two-Factor Authentication in cPanel
- Click Remove Two-Factor Authentication
- Confirm the action
⚠️ Disabling 2FA reduces your account security and is not recommended unless necessary.
If You Lose Access to Your 2FA Device
If you cannot generate a 2FA code (for example, due to a lost or replaced device) and do not have backup access:
- Contact Firstserv support
- You will be required to provide identity verification (ID)
- Our team will assist in disabling or resetting 2FA for your account
Enabling 2FA is one of the most effective ways to secure your hosting account. If you need assistance with setup, the Firstserv support team is always available to help.
