BetterShield

Set up two-factor sign-in and passkeys

5 min read

Turn on two-factor sign-in with an authenticator app and backup codes, add passkeys, require them by role, and help a user who lost their device.

Two-factor sign-in (two-factor authentication, or 2FA, sometimes called MFA) asks for a six-digit code from an authenticator app after the password. A passkey signs you in with your fingerprint, face or device PIN. Administrators manage both on BetterShield › Protect › Two-Factor; everyone else uses their own profile screen.

The summary at the top

Three tiles show Your two-factor (Off until you set it up), Two-factor required for and Passkey-only sign-in for (both no roles by default).

Your sign-in: two-factor

The Two-factor authentication card:

  1. Press Set up two-factor.
  2. Open any authenticator app that makes six-digit codes, such as 1Password, Google Authenticator, Microsoft Authenticator, Authy or Bitwarden. Scan the QR code, or type the Manual entry key.
  3. Enter the code the app shows and press Confirm code.
  4. Store the ten backup codes (Copy codes or Download as a file). They are shown only once, and each works once.
  5. Press the I have stored these codes button to turn two-factor on.

Nothing changes at sign-in until step 5. Cancel at step 3 discards the setup.

Once it is on, the card shows how many backup codes are unused. Under New backup codes, enter an App code or backup code and press Issue new codes; the new set replaces every old code. Under Turn off, enter a current code and press Turn two-factor off. Application passwords for connected tools keep working.

Your sign-in: passkeys

On the Passkeys card, type Name this device, press Add a passkey, and confirm on your device. A passkey is an extra way in: your password, codes and recovery link keep working. Each account can hold 10. Passkeys need HTTPS; without it, the card says why. Each passkey shows when it was last used, and Remove deletes it after you confirm.

Once any account has a passkey, the WordPress sign-in page (wp-login.php) shows Sign in with a passkey. A passkey unlocked with a fingerprint, face or PIN counts as both factors. One that only asks for a touch still needs the app code on a two-factor account, and is not accepted on its own.

What the site requires

OptionWhat it doesWhy it mattersDefault
Require two-factor of a roleAccounts in the ticked roles are asked to set up two-factor, with a countdown on every dashboard page. After the grace period, the dashboard sends them to set it up until they do.Sign-in is never blocked: it is enforced in the dashboard, after the password, and safe mode stands it down.No roles
Grace period, in days0 to 90, counted from when an account first met the requirement. Zero asks immediately.Existing accounts get the full window.14
Sign in with a passkey onlyFor ticked roles, an account’s password stops signing it in once it has added a passkey. A line per role shows how many have one.A password that cannot sign anyone in cannot be phished, guessed or reused from a breach.No roles

Press Save requirement under each. Adding a role to Require two-factor of a role first checks your recovery link or printed recovery codes, as a sign-in hardening fix does.

Passkey-only sign-in has these safeguards:

  • Nobody is refused until they hold a passkey. Others keep their password and are asked on their dashboard.
  • Adding a role is refused unless the site has a working recovery link or printed recovery codes (Protect › Recovery), and unless passkeys work on the site.
  • A refused password gets a message pointing to the passkey button. XML-RPC needs an application password instead.
  • If the passkey is lost, the recovery link, a printed recovery code, or removing the last passkey brings password sign-in back.

On a WooCommerce store, customers set up both on My Account › Sign-in security. A role WooCommerce keeps out of the dashboard is not asked by Require two-factor of a role, but can still set it up there.

Set up from your profile

Anyone signed in can use their own Profile screen:

  • Two-factor sign-in: Set up two-factor, scan the code or type the key, enter the Code from the app, press Confirm code, store the ten codes, then press the I have stored these codes button. Later, Issue new backup codes asks for a current code first.
  • Passkeys: Name this device, then Add a passkey.

Signing in

After the password, the Authentication code screen takes the app’s current code or an unused backup code. After ten wrong codes in an hour, codes for that account are not checked for a while.

When someone loses their device

  1. They sign in with a backup code, then issue a new set.
  2. If the codes are gone too, an administrator opens Users, edits the account, and under Two-factor sign-in presses Turn off two-factor for this account. The person signs in with their password and sets it up again.
  3. For a passkey-only account, an administrator can untick its role under Sign in with a passkey only, which brings password sign-in back for that role. A role the network requires cannot be unticked on one site.

If you are locked out yourself, use your recovery link.

Multisite

On BetterShield › Network, Require two-factor across the network (with its own Grace period, in days) and Passkey-only roles across the network set a floor for every site. A site can add roles but not remove the network’s, and the shorter grace period applies. Adding a passkey-only role needs a working recovery link or printed codes on every site. Both start Not set.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield