To enhance the security of your Plesk account, enabling Two-Factor Authentication (2FA) is highly recommended. This guide will walk you through setting up 2FA using Google Authenticator or any other Time-based One-Time Password (TOTP) application.

Setting Up Two-Factor Authentication

To enable 2FA on your Plesk account, follow these steps:

  1. Log in to your Plesk control panel using your username and password.
  2. Navigate to the "Tools & Settings" section. This is usually found in the left-hand menu or at the bottom of the dashboard.
  3. Select "Security" from the list of options.
  4. Click on "Two-Factor Authentication" under the security settings.
  5. In the Two-Factor Authentication setup page, click on "Enable 2FA".
  6. A QR code will be displayed. Use your TOTP application (such as Google Authenticator) to scan this QR code. If you cannot scan the QR code, you can manually enter the secret key provided next to the QR code.
  7. After scanning the QR code or entering the secret key, your TOTP app will generate a 6-digit verification code.
  8. Enter this verification code in the field provided on the Plesk setup page and click "Verify".
  9. If the code is correct, you will see a confirmation that 2FA has been successfully enabled. You can now close the setup window.

Backup Codes

It's crucial to have backup codes in case you lose access to your TOTP application. Here’s how to generate and store them:

  1. In the Two-Factor Authentication section of Plesk, click on "Generate Backup Codes".
  2. A list of one-time backup codes will be displayed.
  3. Download or copy these codes and store them in a secure location. Do not share these codes with anyone.

Troubleshooting

If you encounter issues while setting up 2FA, here are some troubleshooting tips:

  • QR Code Not Scanning: Ensure your device's camera is clean and the lighting conditions are good. Alternatively, manually enter the secret key.
  • Incorrect Verification Code: Make sure you are using the correct TOTP application and that it is synchronized with the current time. If the issue persists, try generating a new QR code or secret key.
  • Lost Access to TOTP App: Use one of your backup codes to log in to Plesk. Immediately after logging in, disable 2FA and set it up again with a new TOTP app or generate new backup codes.

By following these steps, you can significantly enhance the security of your Plesk account with Two-Factor Authentication. Always keep your backup codes safe and accessible in case of emergencies.