Two-factor authentication (2FA) adds a one-time verification code to your Plesk login. Even if someone learns your password, they still cannot sign in without the code generated by your authenticator app.
Before you start
- Make sure you can log in to Plesk (open it from My.GARMTECH → your hosting service → Login to Plesk).
- Install an authenticator app on your phone: Google Authenticator, Microsoft Authenticator, or another TOTP/MFA app.
- Enable automatic time on your phone. Incorrect time is the most common reason for “invalid code”.
Enable 2FA in Plesk
- Log in to Plesk.
- Open My Profile (top-right user menu).
- Find the Multi-Factor Authentication (MFA) section and click the setup/enabled link.
- Scan the QR code with your authenticator app (add a new account by scanning).
- Enter the current 6-digit code from the app in Plesk and click OK.
Tip: If you see a “Remember this device” option, you can enable it for your personal computer. Avoid using it on shared/public devices.
Test your login
- Log out from Plesk.
- Log in again with your username and password.
- When prompted, enter the current code from your authenticator app.
Disable 2FA
- Log in to Plesk.
- Go to My Profile → Multi-Factor Authentication (MFA).
- Disable MFA and save changes.
If you lost your phone or codes do not work
- Check phone time sync (date & time set to automatic).
- If your authenticator supports cloud/backup restore, restore it on the new device.
- If you cannot log in at all, open a ticket in My.GARMTECH and request a 2FA reset for your Plesk user (include the affected service/domain for verification). (/tickets/create/step1)