Two‑Factor Authentication (2FA) adds an extra layer of security to reseller accounts in WebHost Manager (WHM). With 2FA enabled, users must provide both their password and a unique time‑based security code generated by an authentication app to log in.
Why Enable 2FA?
-
Protects reseller accounts against stolen or weak passwords.
-
Reduces risk of unauthorized access to WHM and cPanel.
-
Ensures compliance with modern security standards.
-
Provides peace of mind for both resellers and their customers.
Setting Up 2FA for Your Account
-
Log in to WHM.
-
In the search box (top left), type factor.
-
Click Two‑Factor Authentication when it appears.
-
Go to the Settings tab:
-
Enter an Issuer name (this is what appears in the authentication app).
-
Click Save.
-
-
Go to the Manage My Account tab:
-
Click Set Up Two‑Factor Authentication.
-
Scan the displayed QR code with your authentication app (e.g., Google Authenticator, Duo Mobile, Authenticator).
-
Alternatively, manually enter the provided Account and Key into your app.
-
Enter the security code generated by the app into WHM.
-
Click Configure Two‑Factor Authentication. 2FA is now active for your reseller account.
-
Managing 2FA for User Accounts
Resellers can also manage 2FA for their users:
-
Log in to WHM.
-
Search for Two‑Factor Authentication.
-
Go to the Manage Users tab.
-
Actions available:
-
Disable 2FA for a specific user → Click Disable next to the account.
-
Disable 2FA for multiple users → Select accounts, click the gear icon, then choose Remove Selected.
-
Disable 2FA for all users → Click the gear icon and select Disable All. To enable 2FA for a user, log in to their cPanel interface and follow the same setup steps.
-
Security Best Practices
-
Encourage all reseller users to enable 2FA.
-
Use authentication apps that support the TOTP algorithm (time‑based one‑time password).
-
Regularly review accounts to ensure compliance.
-
Avoid disabling 2FA unless absolutely necessary.
Notes
|