Two-factor authentication (2FA / MFA) for all your users / user roles.
Multi-Factor Authentication – Two Factor (2FA/OTP) – Multi-factor authentication can be configured for any TOTP-based authentication method like Google Authenticator, Microsoft Authenticator, etc to secure your WordPress website. It also supports OTP Over SMS, OTP Over Email, Duo Authenticator, Microsoft Authenticator, OTP Over WhatsApp, OTP Over Telegram, and many more authentication methods.
Note: The two-factor plugin is GDPR Compliant and supports a wide variety of Language Translations
You only need to configure Google Authenticator and other Two Factor Authentication ( 2FA ) methods once even on a multisite environment. This configuration will then be automatically reflected on the entire network. This is available for Google Authenticator, Duo Authenticator, Microsoft Authenticator, Security Questions, LastPass, Authy, miniOrange methods, OTP over SMS, and OTP over Email. It is supported only if you are using our MFA cloud services.
Premium Plugin(All Inclusive) Features
You can configure multiple WordPress 2FA methods like google authenticator, OTP over Email, OTP over SMS, etc, and choose any one method from a list of configured methods to use as 2FA for your WordPress website. Multi-factor authentication is helpful for cases such as when you do not have your phone and cannot access your TOTP app for login. You can then use other MFA methods like OTP over Email to login.
Check all the features other than MFA ( 2FA ) here: miniOrange Website.
Multi-Factor authentication uses miniOrange APIs to communicate between your WP website and miniOrange. To keep this communication secure, we ask you to register and assign API keys specific to your account. This way your account and users’ calls can only be accessed by API keys assigned to you.
Adding to this, you can also use the same account on multiple applications and your users do not have to maintain multiple accounts on WordPress 2FA like Google Authenticator. Single code generated in Google Authenticator will be enough to login to all sites. With this, you can also achieve sync of two factor authentication across multiple sites. This helps to provide a secure WP 2FA cloud solution.
With OTP over WhatsApp, users can receive OTP via the world’s most popular messaging app, WhatsApp as 2FA. Click here to download the Login with WhatsApp plugin.
This add-on allows you to use Firebase SMS transactions to send OTP via SMS as 2FA. Using this add-on, you can get upto 10,000 SMS transactions a month to send OTPs. For further information, please contact us at [email protected].
This is an add-on which allows OTP Verification to be enabled for selected list of countries only. OTP Verification for any other country not in the list will be blocked.
This is an add-on which allows Admin to send Custom SMS and OTP Verification codes in bulk. Upload the CSV file or enter the numbers manually along with the SMS template that needs to be sent in bulk.
This is an add-on which allows Blocking of OTP codes from being sent out before the set timer is up. This Addon helps in limiting malicious users or unwanted OTP requests to be made by blocking the user for the time limit set.
This is an add-on which allows OTP Verification over Phone Call instead of SMS. The code will be received via a phone call to the customer.
This is an add-on which allows User Verification via accept/reject links received on the email instead of OTP codes.
Plugins > Add New
from your WP Admin dashboard.Multi-Factor Authentication. Find and Install
Multi-Factor AuthenticationminiOrange 2 Factor Authentication (2FA)
and download it.miniorange-login-security (2FA)
directory to your /wp-content/plugins/
directory.Video Guide :
Setup different 2-Factor methods (2FA/OTP)
2 Factor plugin settings. (2FA/OTP)
Advance plugin settings (2FA/OTP)
Login form option1 (Enter username) (2FA/OTP)
Login form option2 (Enter username) (2FA/OTP)
QR Code Authentication Login Screen ( Authenticate your mobile ) (2FA/OTP)
OTP Login Screen ( OTP over SMS, Phone Call Verification, Soft Token, Google Authenticator ) (2FA/OTP)
Push Notification and Email Verification (2FA/OTP)
You can obtain access to your website by one of the below options:
For detailed information, Please check on our website.
You can also check our video Tutorial:
You can use google authenticator as the backup method for your specific user or all users in the premium version of the two-factor authentication. [PREMIUM FEATURE]
You can select the roles under the Login Settings tab to enable the plugin role-wise. [PREMIUM FEATURE]
If a user has not set up Two-Factor yet, the user has to register by inline registration that will be invoked during the login.
You can select the two-factor authentication methods under the Login Settings tab. The selected authentication methods will be shown to the user during inline registration for example if you select Google Authenticator it will be shown on login. [PREMIUM FEATURE]
The OTP is sent to the email address with which you have registered with miniOrange. If you can’t see the email from miniOrange in your emails, please make sure to check your SPAM folder. If you don’t see an email even in the SPAM folder, please submit a query in our Support Section in the plugin or you can contact us at [email protected].
Select the radio button next to Google Authenticator/Authy App and select the phone type and then scan the QR Code by Google Authenticator App. Enter the 6-digit code in the textbox and click on Save and verify button.
Select the radio button next to Google Authenticator/Authy App and select the phone type and then scan the QR Code by Authy 2-Factor Authentication (2FA/TFA) App. Enter the 6-digit code from the Authy App into the textbox available and click on Save and Verify button.
There are two cases according to the page you see –
1. Login with miniOrange screen: You should click on the forgot password link. You will get a new password on your email address with which you have registered with miniOrange. Now you can login with the new password.
2. Register with the miniOrange screen: Enter your email ID and any random password in the password and confirm the password input box. This will redirect you to log in with a miniOrange screen. Now follow the first step.
If you have a custom login form other than wp-login.php then we will provide you with the shortcode. Shortcode will work only for the customized login page created from WordPress plugins. We are not claiming that it will work with all the customized login pages. In such a case, custom work is needed to integrate two factors with your customized login page. You can submit a query in our Support Section in the plugin or you can contact us at [email protected] for more details.
If you have Woocommerce theme login then go to Advanced Options Tab and check Enable Two-Factor for Woocommerce Front End Login. If you need any help setting up 2-Factor for your Woocommerce theme login form, please submit a query in our Support Section in the plugin or you can contact us at [email protected].
The limit login attempt kind of plugin limits the number of login attempts and blocks the IP temporarily. So if you are using 2 factors (2fa/TFA) along with these kinds of plugins then you should increase the login attempts (minimum 5) so that you don’t get locked out yourself.
Our Two-Factor plugin is compatible with most of the security plugins, but if it is not working for you. Please submit a query in our Support Section in the plugin or you can contact us at [email protected].
If you are using Async JS and CSS Plugin. Please go to its settings and add jquery to the list of exceptions and save settings. It will work. If you are still not able to get it right, Please submit a query in our Support Section in the plugin or you can contact us at [email protected].
We support all types of phones. Smart Phones, Basic Phones, Landlines, etc. Go to Setup Two-Factor Tab and select the Two-Factor method of your choice from a range of 8 different options.
You can select OTP over SMS, Phone Call Verification, or Email Verification as your Two-Factor method. All these methods are supported on basic phones.
You can select Email Verification or Security Questions (KBA) as your Two-Factor method.
If your Security Questions (KBA) are configured then you will be asked to answer them when you are logging in from your phone.
You should go to Login Settings Tab and check Login with Phone Only checkbox to hide the default login form.
You should go to Login Settings Tab
You can login using our alternate login method. Please follow the below steps to login:
You can login using our alternate login method apart from 2FA. Click on the Forgot Phone link and you will get 2 alternate methods to login. Select “Send a one-time passcode to my registered email” to authenticate by OTP Over Email or Select “Answer your Security Questions (KBA)” to authenticate by knowledge-based authentication.
Click on the Settings Icon on top right corner in miniOrange Authenticator App and then press Sync button under ‘Time correction for codes’ to sync your time with miniOrange Servers. If you still can’t log in then please email us at [email protected] or Contact us. Soft Token method is just like google authenticator method.
You should go to Setup Two Factor (2FA) Tab and click on Reconfigure to reconfigure 2-Factor with your new phone.
miniOrange authentication service has 15+ authentication methods. One-time passcodes (OTP) over SMS, OTP over Email, OTP over SMS and Email, Out of Band SMS, Out of Band Email, Soft Token, Push Notification, Security Questions, Mobile Authentication (QR Code Authentication), Phone Verification, Device Identification. To know more about authentication methods, click here. If you want to have any other 2-factor for your WordPress site, please email us at [email protected] or Contact us.