---
title: "Enabling Two-Factor Authentication in WHM"
source: "https://docs.nexcess.com/hosting/control-panel/whm/security/enabling-two-factor-authentication-in-whm/"
description: "Secure your server by enabling Two-Factor Authentication (2FA) in WHM. Learn how to configure 2FA for root access and manage cPanel users."
vertical: "Hosting"
date: "2024-03-04"
last_modified: "2026-07-02"
---

# Enabling Two-Factor Authentication in WHM

Before Two-Factor Authentication can be enabled for your user, they will need to download a two-factor authentication app like [Duo Mobile](https://duo.com/solutions/features/two-factor-authentication-methods/duo-mobile) or [Google Authenticator](https://support.google.com/accounts/answer/1066447?hl=en). With this app, you will enter the key or scan the QR Code given during the Two-Factor Authorization process

Two-factor authorization means that instead of just a password, you will also need a rotating authentication token along with the password (two factors) to log into WHM. Only the correct combination of the first and second factor will allow you to log in and access your server through WHM. In addition to adding two-factor authorization for users in WHM, you can also [enable it for users in your Liquid Web account](https://www.liquidweb.com/help-docs/enabling-two-factor-authentication-for-users/).

1. To enable two-factor authorization in WHM, log into WHM as root.
2. Type the word *two* in the search bar on the left-hand side of the page to bring up the menu item, Two-Factor Authentication.  
    ![search word two entered](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_ucSceE.png)
3. Select **Two-Factor Authentication**.  
    ![two factor authentication link highlighted](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_I1WkXC.png)
4. This will take you to the Two-Factor Authentication home page. It is set to disabled by default. Click the button to enable.  
    ![two factor enabled](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_Vd4JNy.png)
5. The **Settings** tab should show your host name as the Issuer. If it does not, enter your host name and click **Save**.
6. The **Manage Users** tab will remain empty until you set up two-factor authentication for each cPanel user you want to have that login method. See our article [Enabling Two-Factor Authentication in cPanel](https://docs.nexcess.com/hosting/control-panel/whm/cpanel/security/enabling-two-factor-authentication-in-cpanel/) to set up your users.  
    ![manage user section](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_RiqWvr.png)
7. Once Two-Factor Authentication is enabled on a cPanel users account, they will show in the Manage Users section.  
    ![whm user list](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_3IFIFl.png)
8. Next, Configure the Two-Factor Authentication in the **Manage My Account** tab.
9. Scan the QR code into your two-factor authentication app on your phone. If you don’t have a scanner, you can enter the credentials under the bar code. ![qr code showing](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_li2yTU.png)  
    ![code for no qr reader](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_GQU66t.png)
10. Enter the authentication code in the authenticator application on your phone.  
    ![enter authorization code](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_qsCLhe.png)
11. Click the **Configure Two-Factor Authentication** button to complete the process. ![configured](https://docs.nexcess.com/wp-content/uploads/2026/06/help.liquidweb.com_e0Szqj.png)
