2FA at scale for WordPress teams

Run two-factor authentication across a whole team: a full 2FA audit log, bulk resets when someone loses a device, trusted devices to keep prompts sane, and session controls for cleanup.

18
event types in the 2FA audit log, from enrollments to lockouts
Bulk
reset 2FA for selected users or the whole site in one action
30 days
default trusted-device window (max 5 devices per user)
Backup codes
so a lost phone is an inconvenience, not a ticket

What it does

Rolling 2FA out to five people is easy. Keeping it healthy across fifty is where the operational features matter: knowing who is enrolled, resetting the colleague who dropped their phone in a lake, and not drowning everyone in prompts on machines they use every day.

How it works

The 2FA audit log records the lifecycle in its own table: methods enabled, disabled and changed, verification attempts with IP, backup codes generated and used, trusted devices added and removed, passkey registrations, lockouts and session events, queryable with filters and statistics, with automatic cleanup of old entries.

When someone is locked out, administrators reset 2FA for selected users (or, in a genuine emergency, for every account at once). Trusted devices cut prompt fatigue by remembering approved hardware for thirty days by default, with notification when a new device appears. Backup codes give users a self-service escape hatch. And 2FA itself is enabled per role, so the requirement lands exactly where you point it.

  • Dedicated 2FA audit log with filtering and statistics
  • Bulk 2FA reset: selected users or site-wide
  • Trusted devices: 30-day default, cap of 5, new-device alerts
  • Backup codes for self-service recovery
  • Bulk session revocation and session automations
  • Per-role 2FA enablement (in the free core)

Documentation

2FA users & sessions

Manage enrollment and active sessions.

Read the guide →

2FA audit logs

The enrollment and verification trail.

Read the guide →

Trusted devices

Fewer prompts on approved hardware.

Read the guide →

Backup codes

Self-service recovery for lost devices.

Read the guide →

2FA at scale questions

Can I force a role to enroll in 2FA?

2FA methods are enabled per role in the free core. Hard enforcement with a grace window currently exists for passkeys; for classic 2FA, role enablement plus the audit log tells you who has and has not enrolled.

Someone lost their phone. What is the fastest fix?

If they have backup codes, they recover themselves. Otherwise an administrator resets their 2FA from the users screen in seconds, with no database surgery.

Related features

Pro

Passkeys & passwordless

Role enforcement with a grace period, built on WebAuthn.

Learn more →
Free

Sessions & presence

Concurrent-login limits and live presence.

Learn more →
Pro

Full activity log

The site-wide trail beyond authentication.

Learn more →

All features →

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.