How to Set Up Two-Step Authentication in DirectAdmin

Two-Step Authentication (2FA) adds a critical second layer of security to your DirectAdmin login. Even if someone obtains your password through a phishing attack, data breach, or brute-force attempt, they still cannot access your account without the time-sensitive verification code from your authenticator app. Setting up 2FA for DirectAdmin takes less than five minutes and dramatically reduces the risk of unauthorized access to your hosting account.

What Is Two-Step Authentication?

Traditional login uses something you know — your password. Two-step authentication adds a second factor: something you have — typically your smartphone. When 2FA is enabled, logging in requires both your password AND a 6-digit code that changes every 30 seconds. This time-based one-time password (TOTP) is generated by an app on your phone and is unique to your account. Without physical access to your phone, attackers cannot log in even with a correct password.

Why Enable 2FA for DirectAdmin?

Your DirectAdmin account controls everything on your hosting — all website files, databases, email accounts, and DNS records. A compromised hosting account can mean complete loss of your website, customer data theft, malware injection, and blacklisting by search engines. Enabling 2FA costs you 10 extra seconds at login but makes brute-force and credential-stuffing attacks essentially impossible.

Requirements

You need an authenticator app installed on your smartphone before starting. The most popular options are:

How to Enable 2FA in DirectAdmin (Step by Step)

  1. Log in to DirectAdmin with your current username and password.
  2. Go to Your Account section and click Two-Factor Authentication.
  3. Click Enable Two-Factor Authentication.
  4. DirectAdmin will display a QR code on screen.
  5. Open your authenticator app on your phone and tap Add Account or the + button.
  6. Choose Scan QR code and point your camera at the QR code on the DirectAdmin screen.
  7. The app will add your DirectAdmin account and immediately start showing a 6-digit code that refreshes every 30 seconds.
  8. Enter the current 6-digit code from your app into the Verification Code field in DirectAdmin.
  9. Click Confirm. DirectAdmin will verify the code and activate 2FA.
  10. Store your backup codes in a safe place — these are used if you lose access to your phone.
Two-Step Authentication page in DirectAdmin Evolution
Two-Step Authentication page in DirectAdmin Evolution
Click the Enable button (circled) to activate Two-Factor Authentication
Click the Enable button (circled) to activate Two-Factor Authentication

Logging In with 2FA Active

Once 2FA is enabled, every DirectAdmin login will have an additional step. After entering your username and password correctly, you will be prompted for your verification code. Open your authenticator app, find your DirectAdmin entry, and type the current 6-digit code. The code is valid for 30 seconds — if it expires, just wait for the next one to appear. Click Login to complete authentication.

Disabling 2FA

If you need to disable 2FA — for example, when switching to a new phone — log in with your password and verification code, go to Two-Factor Authentication settings, and click Disable. You will need to confirm this action. You can then re-enable and re-scan the QR code from your new device.

Understanding TOTP: How the Time-Based Code Works

DirectAdmin's Two-Factor Authentication uses the TOTP (Time-based One-Time Password) standard defined in RFC 6238. Understanding how it works helps you use it correctly and troubleshoot problems when they arise.

When you scan the QR code with your authenticator app, you are storing a secret key shared between DirectAdmin and your phone. Every 30 seconds, both your phone and DirectAdmin's server independently calculate the same 6-digit code using the shared secret and the current Unix timestamp. When you enter the code at login, DirectAdmin runs the same calculation and checks that your input matches. If the codes match within the valid time window, access is granted.

Choosing and Setting Up Your Authenticator App

All TOTP-compatible authenticator apps work with DirectAdmin. Here is a comparison of the most popular options to help you choose the right one for your situation:

Any of these apps will work. Scan the QR code from DirectAdmin using your chosen app's "Add Account" or "+" button, then verify the first code to complete the setup.

Saving Backup Recovery Codes: What to Do and What to Avoid

When you first enable 2FA in DirectAdmin, the system provides a set of backup recovery codes. These single-use codes allow you to log in when you cannot access your authenticator app — for example, when your phone is lost, stolen, broken, or wiped. Treating these codes as critical security assets is essential.

How to Store Backup Codes Safely

Each backup code can only be used once. After you use one to log in, it is immediately invalidated. Once logged in with a backup code, your first action should be to re-scan a new QR code on your replacement phone and re-enable 2FA so your account is protected again.

Disabling and Resetting 2FA: User and Admin Options

There are scenarios where you need to disable or reset 2FA: switching to a new phone, recovering from a lost device, or managing 2FA for users under your account. DirectAdmin provides options at both the user level and the admin level.

Disabling 2FA as the Account Owner

If you have access to your current OTP codes, disabling 2FA is straightforward: log in with your password and OTP, navigate to Two-Factor Authentication settings, and click Disable. You will be asked to confirm with your current OTP. After disabling, you can immediately set up 2FA again on your new device by scanning a fresh QR code.

Using a Backup Code to Disable 2FA

If your phone is unavailable but you have a backup code, use it at the OTP prompt during login. Once logged in, go to Two-Factor Authentication settings and disable 2FA so you can re-enable it with a new device. Remember that each backup code is single-use — once used, it cannot be used again.

Admin Override for Sub-accounts

If a user or reseller under your DirectAdmin admin account has lost access to their authenticator and has no backup codes, you can reset their 2FA from the admin panel. Navigate to Admin Level > List Users, select the affected user, and choose Reset Two-Factor Authentication. This immediately disables their 2FA and allows them to log in with just their password on the next attempt. They should then immediately re-enable 2FA on a new device.

Before performing an admin 2FA reset, always verify the requesting user's identity through an independent channel — for example, through a support ticket from their registered email address. Social engineering attacks often involve convincing an admin to disable 2FA on a target account.

What to Do If You Lose Your Authenticator

If you lose your phone or uninstall the authenticator app, you will need your backup codes to log in. If you did not save the backup codes, contact your hosting provider (AsiaGB support) to disable 2FA on your account after verifying your identity. This is why saving backup codes when you first enable 2FA is essential.

Enable 2FA First: The very first action you should take after gaining access to a new DirectAdmin account is enabling Two-Factor Authentication. Your hosting account is a high-value target — it controls your entire web presence. Do not wait until after you have uploaded files and data. Enable 2FA immediately, before anything else.

Secure Hosting with High-Security Control Panel

AsiaGB hosting plans include DirectAdmin with 2FA, login keys, SSH key authentication, and multiple layers of security for your account.

View Hosting Plans