On This Page
On This Page
Two-Factor Authentication (2FA)
Overview
A Pro Security module that adds two-factor login for selected roles—email OTP and/or authenticator (TOTP). Empty role list means nothing is enforced. Optional grace period and trusted devices (off by default). Default can require application passwords for REST/XML-RPC for enforced roles—soft conflict with Disable Application Passwords (that requirement is disabled when DAP is on). Temporary Login token logins bypass 2FA by design; Magic Login may optionally bypass (default off). Social login is a separate auth path. Requires a valid WP PowerSuite license.

- Admin/editor hardening on production sites
- Agency client sites with privileged roles
- Compliance-minded memberships with role selection
Features
Role-based enforcement
Email OTP and/or TOTP
Attempt limits
Optional grace / trusted devices
API awareness
Documented bypass paths
Use Cases
- Protect administratorsEnforce TOTP for administrator (and maybe editor) only.
- Agency client baselinesRequire 2FA on privileged roles before handoff.
- Email OTP for less technical staffOffer email codes when authenticator apps are a support burden.
Frequently Asked Questions
What does Two-Factor Authentication (2FA) do in WP PowerSuite?
It adds two-factor login for selected roles—extra proof beyond the password.
How do I enable Two-Factor Authentication (2FA) in WP PowerSuite?
Activate a WP PowerSuite license, enable the module, select roles and methods (email/TOTP), and save. Users complete setup on next login.
Who should use Two-Factor Authentication (2FA)?
Sites that need privileged-role hardening beyond passwords alone.
Does Temporary Login respect 2FA?
Token-based Temporary Login bypasses 2FA by design so vendors can enter—treat those links like secrets.
Is Two-Factor Authentication (2FA) a free or Pro module in WP PowerSuite?
It is a Pro module and requires a valid WP PowerSuite license.

