# Run BetterShield on a multisite network

Use BetterShield on WordPress multisite: network activation, the Network screen, rules set for every site, and what each site keeps for itself.

On a multisite network, nearly everything BetterShield does belongs to each site. Network administrators also get a **BetterShield** menu in Network Admin, with **Network** and **Activity**.

## Network activation

- **Network Activate** sets up every site as a single site is set up: a first audit, and a recovery link emailed to that site's own administration address.
- A site created later is set up the same way.
- On a very large network, activation can stop before reaching every site. A site it missed shows **Not set up here yet** on the Network screen; opening its BetterShield dashboard sets it up.

## The Network screen

### Every site on this network

One row per site: **Site** (linking to its BetterShield dashboard), **Score** with grade, **Open findings**, **Last audit** and **State**. **State** shows **Carried over** or **Not yet carried over** (see below), and **No way back in** when the site has no working recovery link.

The figures are each site's own last audit; this screen never runs one. They are kept for up to an hour; **Read them again now** rereads them. **Show more sites** loads the next 200.

### Set once, for every site

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Require two-factor across the network** | Tick roles, set **Grace period, in days** (0 to 90), press **Save**. | A floor: a site can add roles, not remove the network's, and the shorter grace period applies. | **Not set** (grace field shows 14) |
| **Passkey-only roles across the network** | Tick roles and press **Save**. Those accounts sign in with a passkey, not a password, on every site. | Adding a role is refused while any site lacks a working recovery link or printed codes, and on a network of more than 200 sites. | **Not set** |
| **Moving the log to the shared tables** | Progress of copying each site's log, findings, agent record and passkeys into tables the network shares: **Not started**, **In progress**, **Waiting to retry** or **Finished**, with **Sites carried over**. | Lets the network screens read across sites. Runs hourly, in small batches, and removes nothing. | Runs by itself |
| **Recovery link for the network** | **Generate recovery link** (later **Generate a new link**) shows one link, once. Opening it pauses enforcement on every site for an hour. | A way back in above any one site. A site's own link opens that site only. | None until generated |
| **Rotate the sign-in keys** | Tick **I understand every other session on every site will end**, then press **Rotate the sign-in keys**. Everyone else signs in again with their password; you stay signed in. | Ends every session on every site. It cannot be put back. | None |
| **Recent changes to the network** | Each change to the two network rules, with **Put back**, which changes every site it reached. Shown once there is one. | | None |

The network recovery link works once and lasts 90 days. Using it issues a new one, emailed to the network's administration address; generating a new one stops the old one.

Changes here need a signed-in browser, and your password again if the main site has **Ask for my password before an action that removes a protection** on.

## What is set for the whole network

- The two-factor and passkey-only floors above.
- The network recovery link, and the network-wide pause it starts.
- The sign-in keys, since one sign-in covers every site.
- Whether usage data is shared, answered by a super admin.

Everything else is per site: findings, hardening fixes, Login & Access, email alerts, the site's recovery link and printed codes, AI assistant and BetterShield Hub connections, and settings. A site's own recovery link and `wp bettershield recover` pause that site only.

## Quick Setup on each site

- Nobody is redirected on network activation. Each site's Quick Setup opens the first time its administrator opens BetterShield.
- Only a super admin is asked about usage data.
- When the network requires two-factor of administrators, **Require two-factor for Administrators** shows ticked and locked.
- Anyone who cannot install and activate plugins, usually a site administrator on a network, skips the recommended plugins step.

## Hardening on a network

| Fix | On a network |
|---|---|
| **Hide sensitive files from visitors** | Main site only. It protects every site, as they share one .htaccess. |
| **Stop PHP running in uploads** | From the main site it covers every site; from another site, that site's uploads only. |
| **Stop uploads directories listing their contents** | Per site: apply it on each site that needs it. |
| **Disable the dashboard file editor** | Changes nothing for a site administrator: the code editors already belong to network administrators. |
| **Change the sign-in address** | This site only. |
| **Tell browsers to refuse plain HTTP** | Every subdomain, set on the main site of a subdomain network, means every site. |
| **Keep low-privilege accounts out of the dashboard** | Never applies to a super admin. |
| **Strengthen and rotate the sign-in keys** | Not available on a site's screen. Rotate from the Network screen. |

## Activity across sites

**BetterShield › Activity** in Network Admin lists every site's activity, each row naming its site, with a **Site** filter (**Every site** by default). It has no export and no daily seals. See [Activity log](/docs/activity-log/).

With Ultra, an **Incidents** tab beside it lists each site's open incidents, ten sites at a time.

## WP-CLI across sites

`wp bettershield activity --sites=all`, or a comma-separated list of site IDs, reads the log across sites and adds a site column. Every other command works on the one site WP-CLI runs against.

```
wp bettershield activity --sites=all --format=csv > network.csv
```

## Related

- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Locked out](/docs/locked-out/)
- [Hardening](/docs/hardening/)
- [Activity log](/docs/activity-log/)
- [Install and set up](/docs/install-and-set-up/)
- [Email alerts](/docs/email-alerts/)
- [WP-CLI commands](/docs/wp-cli-commands/)
