{"id":66126,"date":"2022-09-07T10:33:29","date_gmt":"2022-09-07T16:33:29","guid":{"rendered":"https:\/\/www.scalahosting.com\/blog\/?p=66126"},"modified":"2024-08-05T10:06:14","modified_gmt":"2024-08-05T16:06:14","slug":"two-factor-authentication-in-spanel","status":"publish","type":"post","link":"https:\/\/www.scalahosting.com\/blog\/two-factor-authentication-in-spanel\/","title":{"rendered":"Two-Factor Authentication in SPanel"},"content":{"rendered":"\n<p>It&#8217;s always a bit shocking to find out that one (or more) of your online accounts has been compromised because hackers have managed to guess your passwords. The truth is, in most cases, this sort of incident should surprise no one.<\/p>\n\n\n\n<p>Statistics show that <strong>as many as 1 in 4 users<\/strong> are prone to protecting their online accounts with passwords like <em>&#8220;123456&#8221; or &#8220;qwerty&#8221;<\/em>. This really makes hackers&#8217; lives easier. We don&#8217;t want that, so we&#8217;ve been working on a proven security feature that protects our<strong> SPanel users<\/strong>.<\/p>\n\n\n\n<p>It&#8217;s called <strong>two-factor authentication (or 2FA)<\/strong>, and it&#8217;s now available on all <a href=\"https:\/\/www.scalahosting.com\/managed-cloud-hosting.html\"><strong>VPS solutions<\/strong><\/a> running our proprietary control panel.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"What-is-Two-Factor-Authentication\"><strong>What is Two-Factor Authentication?<\/strong><\/h2>\n\n\n\n<p><strong>Usernames and passwords <\/strong>have been around since the 1960s and are an integral part of our online lives. Even now, so many decades after they first appeared, we still use them for anything from checking our emails to managing our money.<\/p>\n\n\n\n<p>However, in recent years, we&#8217;ve realized that passwords are not perfect, and we&#8217;ve been looking at <strong>additional methods for keeping our online data safe<\/strong>. <strong>Two-factor authentication<\/strong> is still a relatively new concept, but its popularity is growing, and more and more vendors are starting to implement it.<\/p>\n\n\n\n<p>Its name comes from the fact that the system verifies your identity after taking into consideration not one but two factors. In addition to the username and password, you need to provide a second piece of information when logging in. Usually, it consists of <strong>a temporary code that<\/strong>, in SPanel&#8217;s case, is <strong>generated by a smartphone application<\/strong>.<\/p>\n\n\n\n<p>Therefore, the 2FA feature verifies that you are who you say you are by confirming that you have access to (and can unlock) your smartphone.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-scaled.jpg\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-1024x683.jpg\" alt=\"Two-Factor Authentication in SPanel, What is Two-Factor Authentication?\" class=\"wp-image-66128\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-1024x683.jpg 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-300x200.jpg 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-768x512.jpg 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-1536x1024.jpg 1536w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/pexels-markus-spiske-8247921-2048x1365.jpg 2048w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Why-Do-We-Need-Two-Factor-Authentication\"><strong>Why Do We Need Two-Factor Authentication?<\/strong><\/h2>\n\n\n\n<p>Put simply, we need two-factor authentication because people are not very good with passwords.<\/p>\n\n\n\n<p>The average internet user has <strong>close to 100 online accounts<\/strong>, and there&#8217;s absolutely no way anyone would be able to create and memorize so many strong and unique passwords.<\/p>\n\n\n\n<p>That&#8217;s why many users opt for <em>easy-to-type and -remember strings like &#8220;123456&#8221;<\/em>. Needless to say, these passwords can be cracked in the blink of an eye. Other users try a bit harder and use things like their dogs&#8217; names, which isn&#8217;t really helping.<\/p>\n\n\n\n<p>During their <a href=\"https:\/\/www.scalahosting.com\/blog\/cyber-attack-guide-brute-force-attacks\/\">brute-force attacks<\/a>, hackers employ lists with millions of entries consisting of both common passwords and popular words we use in our everyday lives. Their botnets can make hundreds of thousands of guesses every second, so it won&#8217;t be long before your favorite sports team&#8217;s name comes up.<\/p>\n\n\n\n<p>Some people understand that only truly random passwords can protect your account effectively. They put time and effort into <strong>creating and memorizing a suitably strong password<\/strong>, but they then go ahead and use it on all their accounts.<\/p>\n\n\n\n<p>The problem with this is that a data breach at <strong>one online service exposes details<\/strong> that can lead to the compromise of accounts at multiple others. In fact, this type of brute-forcing is so common, it has its own technical term \u2013 <strong>credential stuffing<\/strong>.<\/p>\n\n\n\n<p>You can find <strong>password management solutions <\/strong>that encrypt and store all your passwords in a single place, but adoption levels show that people are still not used to the &#8220;all eggs in one basket&#8221; approach.<\/p>\n\n\n\n<p>The problem is clear enough, and so are the reasons behind it. Many people say that the only way to solve it is to <strong>find a better alternative to the username-and-password system<\/strong>. However, at this point, we simply don&#8217;t have it, so the only thing we can do is introduce another component to the verification process. This is what <strong>2FA<\/strong> does.<\/p>\n\n\n\n<p>With two-factor authentication, hackers <strong>can&#8217;t compromise your account with a simple username-and-password combination<\/strong>. They need additional data that should be inaccessible to them if the 2FA system is implemented correctly.<\/p>\n\n\n\n<p>For example, the code (sometimes referred to as token) you&#8217;ll need to provide in order to log in to your SPanel account is generated on your smartphone. When 2FA is activated, your phone and <a href=\"https:\/\/www.scalahosting.com\/spanel.html\"><strong>SPanel<\/strong><\/a> use complex cryptography to <strong>synchronize the tokens without transmitting them over the internet<\/strong>. Hackers can&#8217;t intercept or guess the codes because they are refreshed every 30 seconds.<\/p>\n\n\n\n<p><em>Let&#8217;s see how it works in action.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept.jpg\"><img decoding=\"async\" width=\"1024\" height=\"744\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept-1024x744.jpg\" alt=\"Two-Factor Authentication in SPanel, Why Do We Need Two-Factor Authentication?\" class=\"wp-image-66129\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept-1024x744.jpg 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept-300x218.jpg 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept-768x558.jpg 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept-1536x1116.jpg 1536w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/Access_Management_-_Cybersecurity_-_Concept-2048x1488.jpg 2048w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><figcaption class=\"wp-element-caption\">Access Management &#8211; Cybersecurity &#8211; Concept<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"How-To-Use-SPanel-2FA-Feature\"><strong>How To Use SPanel&#8217;s 2FA Feature<\/strong><\/h2>\n\n\n\n<p>Our new two-factor authentication feature is available to anyone on an SPanel server. This includes <strong>administrators, account owners, sub-users, and even webmail users<\/strong>. To make the option available, you simply need to flick a toggle switch inside SPanel&#8217;s admin area.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Enabling 2FA in SPanel<\/strong><\/h3>\n\n\n\n<p>Log in to your SPanel Admin account and go to <strong>Server Settings<\/strong>. Enable the <strong>Two-Factor Authentication (2FA) <\/strong>toggle and click <strong>Apply<\/strong> to make the option available for people with access to your server.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/2.png\"><img decoding=\"async\" width=\"1024\" height=\"544\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/2-1024x544.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel\" class=\"wp-image-66130\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/2-1024x544.png 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/2-300x159.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/2-768x408.png 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/2.png 1254w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>Bear in mind that this only <strong>activates the feature on the VPS<\/strong>. It&#8217;s up to admins and account owners to decide whether they want to use it. You can also use the two toggle switches below to make 2FA a part of your security policy.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/3.png\"><img decoding=\"async\" width=\"746\" height=\"429\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/3.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 2\" class=\"wp-image-66131\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/3.png 746w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/3-300x173.png 300w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>With the first one, all admin accounts, including yours, will be <strong>forced to use two-factor authentication<\/strong>. The second toggle switch enables 2FA for all other users. This includes account owners, sub-users, and people who check their emails via <strong>SPanel&#8217;s Webmail feature<\/strong>.<\/p>\n\n\n\n<p>If 2FA is not enforced, every admin user, account owner, and sub-user can enable it by clicking on their username in the top-right corner of the screen and selecting <strong>Manage 2FA<\/strong>.<\/p>\n\n\n\n<p><strong>Here&#8217;s what it looks like in the Admin Interface:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4.png\"><img decoding=\"async\" width=\"1024\" height=\"168\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4-1024x168.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 3\" class=\"wp-image-66132\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4-1024x168.png 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4-300x49.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4-768x126.png 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4-1536x252.png 1536w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/4.png 1899w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>And this is what you see in the User Interface:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/15.png\"><img decoding=\"async\" width=\"1024\" height=\"204\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/15-1024x204.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 4\" class=\"wp-image-66133\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/15-1024x204.png 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/15-300x60.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/15-768x153.png 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/15.png 1380w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>Webmail users can turn on 2FA on their own by going to the Webmail login page and deselecting the <strong>Automatically load Rainloop webmail<\/strong> checkbox.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/5.png\"><img decoding=\"async\" width=\"395\" height=\"388\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/5.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 5\" class=\"wp-image-66134\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/5.png 395w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/5-300x295.png 300w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>After they enter their email address and password, they&#8217;ll see a list of options for controlling various aspects of their email accounts. Among them is the <strong>2FA option<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/6.png\"><img decoding=\"async\" width=\"1024\" height=\"191\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/6-1024x191.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 6\" class=\"wp-image-66135\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/6-1024x191.png 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/6-300x56.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/6-768x143.png 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/6.png 1282w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>The interface is the same for all users, and it&#8217;s about as simple as it gets. You have a single toggle switch and a <strong>Save <\/strong>button.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/7.png\"><img decoding=\"async\" width=\"861\" height=\"307\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/7.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 7\" class=\"wp-image-66136\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/7.png 861w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/7-300x107.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/7-768x274.png 768w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>If you have full access to the Admin Interface, you can<strong> enable 2FA for individual users<\/strong>. Simply open the <strong>Actions<\/strong> drop-down next to the account you want to modify and select <strong>Manage 2FA<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13.png\"><img decoding=\"async\" width=\"1024\" height=\"405\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13-1024x405.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 8\" class=\"wp-image-66137\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13-1024x405.png 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13-300x119.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13-768x304.png 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13-1536x608.png 1536w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/13.png 1577w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>Similarly, if you own an <strong>SPanel user account<\/strong>, you can enable 2FA for sub-users from the <strong>Manage Users<\/strong> section.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/14.png\"><img decoding=\"async\" width=\"1024\" height=\"235\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/14-1024x235.png\" alt=\"Two-Factor Authentication in SPanel, Enabling 2FA in SPanel 9\" class=\"wp-image-66138\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/14-1024x235.png 1024w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/14-300x69.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/14-768x177.png 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/14.png 1292w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Using-2FA-in-SPanel\"><strong>Using 2FA in SPanel<\/strong><\/h2>\n\n\n\n<p>Configuring your phone to <strong>generate 2FA tokens<\/strong> is just as straightforward. Your first job is to install a <strong>2FA application<\/strong> on your phone or tablet. There are a few alternatives, but unless you have personal preferences for a particular one, <em>Google Authenticator<\/em> is probably your best bet. It&#8217;s available on <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.google.android.apps.authenticator2&amp;hl=en&amp;gl=US\">Google Play<\/a> and the <a href=\"https:\/\/apps.apple.com\/us\/app\/google-authenticator\/id388497605\">App Store<\/a>, it&#8217;s lightweight, and it&#8217;s easy to install.<\/p>\n\n\n\n<p>With the app set up on your phone, you can go back to SPanel, enable the 2FA toggle switch, and click <strong>Save<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/8.png\"><img decoding=\"async\" width=\"853\" height=\"315\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/8.png\" alt=\"Two-Factor Authentication in SPanel, Using 2FA in SPanel\" class=\"wp-image-66139\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/8.png 853w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/8-300x111.png 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/8-768x284.png 768w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>SPanel will load a new page with a <strong>setup key and a QR code<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/9.png\"><img decoding=\"async\" width=\"375\" height=\"805\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/9.png\" alt=\"Two-Factor Authentication in SPanel, Using 2FA in SPanel 2\" class=\"wp-image-66140\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/9.png 375w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/9-140x300.png 140w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>Open <strong>Google Authenticator<\/strong> on your mobile device and click the <strong>+<\/strong> button in the bottom right corner. You can enter the setup key manually, but if you have a working camera, you&#8217;ll most likely prefer to scan the QR code.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/10.png\"><img decoding=\"async\" width=\"447\" height=\"955\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/10.png\" alt=\"Two-Factor Authentication in SPanel, Using 2FA in SPanel 3\" class=\"wp-image-66141\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/10.png 447w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/10-140x300.png 140w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>The <strong>QR gives Google Authenticator all the required information<\/strong>, and the app starts generating 2FA tokens immediately.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/11.png\"><img decoding=\"async\" width=\"447\" height=\"955\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/11.png\" alt=\"Two-Factor Authentication in SPanel, Using 2FA in SPanel 4\" class=\"wp-image-66142\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/11.png 447w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/11-140x300.png 140w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>Next to your token, there&#8217;s an indicator showing you how much time you have before it refreshes.<\/p>\n\n\n\n<p>The last thing you need to do to activate two-factor authentication for your account is to enter a valid 2FA token in the field below the QR code SPanel displays.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><a href=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/12.png\"><img decoding=\"async\" width=\"375\" height=\"805\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/12.png\" alt=\"Two-Factor Authentication in SPanel, Using 2FA in SPanel 5\" class=\"wp-image-66143\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/12.png 375w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2022\/09\/12-140x300.png 140w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/a><\/figure>\n\n\n\n<p>With two-factor authentication enabled, SPanel will ask you for a valid 2FA token every time you try to log in to your account.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Conclusion\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p>The humble password has failed us far too many times to be considered a <strong>secure form of authentication<\/strong>, especially now, when password cracking tools and spilled login credentials are so easy to come by. However, for all its faults, we&#8217;re unlikely to <strong>see the back of the traditional login system any time soon.<\/strong><\/p>\n\n\n\n<p>That&#8217;s why we need all the help we can get to make it more secure. Two-factor authentication may not solve all your security problems, but it could very well be enough to stop an advanced brute-force attack.<\/p>\n\n\n\n<p>In light of this, it makes no sense to ignore it.<\/p>\n\n\n<div class=\"shortcode-cta-new-wrap row spanel\">\r\n    <img decoding=\"async\" class=\"shortcode-logo\" src=\"\/blog\/images\/shortcode-bg-new-logo-spanel.svg\" alt=\"shortcode-logo\" title=\"shortcode-logo\"\/>\r\n    <div class=\"shortcode-cta-img col-10 col-sm-7 col-md-5\">\r\n        <img decoding=\"async\" class=\"shortcode-bg\" src=\"\/blog\/images\/shortcode-bg-new-spanel.webp\" alt=\"shortcode-bg\" title=\"shortcode-bg\"\/>\r\n    <\/div>\r\n    <div class=\"shortcode-cta-content col-12 col-md-7\">\r\n        <div class=\"content\">\r\n            <div class=\"heading\">Revolutionize Your Hosting Management - Join the SPanel Family<\/div>\r\n            <div class=\"list-wrap\">\r\n                <div class=\"list\">\r\n                    <div><b>Effortless Server Management through Powerful Tools<\/b><\/div>\r\n                    <div><b>Anytime Unconditional Money-back Guarantee<\/b><\/div>\r\n                    <div><b>24\/7 Expert Support and Free Website Migration<\/b><\/div>\r\n                <\/div>\r\n            <\/div>\r\n            <div class=\"btn-wrap row\">\r\n                <div class=\"col-auto\">\r\n                    <a class=\"button green\" href=\"https:\/\/www.scalahosting.com\/spanel.html\">Start Now<\/a>\r\n                <\/div>\r\n                <div class=\"col-auto\">\r\n                    <button class=\"button blue_outer\" title=\"Contact Sales\" onclick=\"chatChangeVisibility(this, 'maximize', {}, 5);\">Chat with our Experts<\/button>\r\n                <\/div>\r\n            <\/div>\r\n        <\/div>\r\n    <\/div>\r\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"FAQ\"><strong>FAQ<\/strong><\/h2>\n\n\n\n<p><strong>Q:<\/strong> <strong>What is two-factor authentication?<\/strong><\/p>\n\n\n\n<p><strong>A:<\/strong> <strong>Two-factor authentication (or 2FA)<\/strong> is a security mechanism implemented during the login process that requires an additional token before it signs you into your account. This token usually comes in the form of a <strong>temporary code<\/strong> sent to you via email or text message or<strong> generated by an application on your smartphone.<\/strong><\/p>\n\n\n\n<p>With 2FA enabled, the username and password combination isn&#8217;t enough to give you access to your account.<\/p>\n\n\n\n<p><strong>Q:<\/strong> <strong>Is 2FA available for all SPanel users or for admins only?<\/strong><\/p>\n\n\n\n<p><strong>A:<\/strong> Two-factor authentication can be used by <strong>everyone on an SPanel server<\/strong>, including admins, account owners, and sub-users. It can even be used for webmail logins. As a server owner, you can activate 2FA for individual accounts or force it on users or admins.<\/p>\n\n\n\n<p><strong>Q:<\/strong> <strong>How are SPanel 2FA tokens generated?<\/strong><\/p>\n\n\n\n<p><strong>A:<\/strong> SPanel uses six-digit codes generated by Google Authenticator (or another compatible application) \u2013 a 2FA mobile application designed specifically for this purpose. You can configure Google Authenticator to <strong>work with your SPanel account simply by scanning a QR code<\/strong>.<\/p>\n\n\n\n<script type=\"application\/ld+json\">\n    {\n      \"@context\": \"https:\/\/schema.org\",\n      \"@type\": \"FAQPage\",\n      \"mainEntity\": [{\n        \"@type\": \"Question\",\n        \"name\": \"What is two-factor authentication?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Two-factor authentication (or 2FA) is a security mechanism implemented during the login process that requires an additional token before it signs you into your account. This token usually comes in the form of a temporary code sent to you via email or text message or generated by an application on your smartphone. With 2FA enabled, the username and password combination isn't enough to give you access to your account.\"\n        }\n      }, {\n        \"@type\": \"Question\",\n        \"name\": \"Is 2FA available for all SPanel users or for admins only?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Two-factor authentication can be used by everyone on an SPanel server, including admins, account owners, and sub-users. It can even be used for webmail logins. As a server owner, you can activate 2FA for individual accounts or force it on users or admins.\"\n        }\n      },{\n        \"@type\": \"Question\",\n        \"name\": \"How are SPanel 2FA tokens generated?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"SPanel uses six-digit codes generated by Google Authenticator (or another compatible application) \u2013 a 2FA mobile application designed specifically for this purpose. You can configure Google Authenticator to work with your SPanel account simply by scanning a QR code.\"\n        }\n      }]\n    }\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s always a bit shocking to find out that one (or more) of your online accounts has been compromised because &#8230;<\/p>\n","protected":false},"author":113,"featured_media":66146,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_analysis_target_kw":"","footnotes":""},"categories":[125],"tags":[],"class_list":["post-66126","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-spanel"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts\/66126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/users\/113"}],"replies":[{"embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/comments?post=66126"}],"version-history":[{"count":3,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts\/66126\/revisions"}],"predecessor-version":[{"id":71167,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts\/66126\/revisions\/71167"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/media\/66146"}],"wp:attachment":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/media?parent=66126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/categories?post=66126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/tags?post=66126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}