Search Results :

×

How to Setup OTP Over Email For WordPress 2FA?


Email OTP authentication/OTP Over Email method involves sending a unique, temporary 2FA code/ Email OTP to the user's registered email address, which the user must enter along with their username and password to login to the WordPress account. OTP Over Email has a straightforward setup, making it an ideal choice for WordPress administrators looking to improve their site's security without complicating the user experience.

Why should you use OTP Over Email or WordPress 2fa SMS as a two-factor authentication method?

  • Ease of Use: Receiving a code via email is straightforward and familiar to most users.
  • No Dependency on Mobile Networks: Users can receive codes as long as they have internet access.

miniOrange Two-Factor Authentication Plugin provides a multitude of two-factor authentication methods. Mainly these methods can be of the following categories:-

  • All Authenticator apps(TOTP) methods
  • OTP Over SMS
  • OTP Over Email

Let's start the OTP Over Email setup with the miniOrange Two-Factor Authentication plugin to make the user's account secure.

You can download miniOrange 2-Factor Authentication(2FA) plugin using the following link:

This plugin can be configured for any TOTP-based/OTP Login 2fa methods like Duo/Microsoft/Google Authenticator. It supports OTP login based 2fa methods [24/7 SUPPORT]

  Tested with 6.0.1

Pre-requisites For Setting Up OTP Over Email as a 2FA method.

To use OTP Over Email as the two-factor authentication method for your WordPress site you need:-

Getting started with the OTP Over Email/SMS Authentication setup

Let’s see how an administrator can set up OTP Over Email for users. This can be done in two very simple ways:-

  1. Setup Wizard
  2. Dashboard of the plugin

1. OTP Over Email setup through Setup Wizard

The setup wizard appears right after the successful installation and activation of the WordPress 2FA plugin. The Wizard helps you set up 2FA(in this case OTP Over Email)

Let’s follow the steps below to set up the OTP Over Email method as 2FA for your users.

    Step 1: Once you have activated the plugin the following screen of the setup wizard appears.

  • Click on the Let’s get started! button.
  • Email OTP Authentication - let's get started button

    Step 2: The wizard guides you to choose any one option for inline registration.
    There are two option under inline registration:-

  • Choose the first option “User should setup 2FA during first login.”
    Choosing this option as name suggests will make user’s compulsorily configure 2FA methods (in this case OTP Over Email).
  • Click on the Continue Setup button.
  • Email OTP Authentication - user should setup 2FA during first login

    Step 3: Next you are guided to choose the user’s role for which you want to set OTP Over Email as a 2FA method.

  • Choose the ”All users” option to set 2FA for all and click on the Continue Setup button.
  • Email OTP Authentication - choose all users
    OR
  • Choose only for a specific roles option.
  • Select the particular role for which you want to set 2FA. (As administrator has been chosen here. This will set the OTP Over Email method as 2FA only for the administrator's role.)
  • Then, click on the Continue Setup button.
  • Email OTP Authentication - choose particular role like admin

    Step 4: Now, it guides you to set the Grace period for your users. There are again two options:-

    1. Users should be directly enforced for 2FA Setup:- If you don’t want to give your users any period to set 2FA you can go with the first option.
    Users will have to set 2FA during their first login to gain access to the account.

    2. Give users a grace period to configure 2FA:- choosing this option will allow you to give your users a certain grace period within which users will be required to set their 2FA. Users will have to set 2FA after the expiration of the grace period.

  • Choose the “Users should be directly enforced for 2FA Setup” option and click on the All Done button.
  • Email OTP Authentication - enfore 2fa for users
  • You have successfully configured the two-factor authentication.
  • Email OTP Authentication - compelted

Steps for users to configure OTP Over Email

After completing the above 2FA setup in a few simple steps, users are prompted to configure a list of two-factor authentication methods, including OTP Over Email.

  • Navigate to the WordPress Login page and enter the user’s login credentials.
  • Email OTP Login - enter username and password and login
  • Choose the “OTP Over Email” radio button. You are prompted to configure a two-factor method while logging in for the very first time.
  • Email OTP Login - Select OTP Over Email
  • Enter the 2FA code /2FA OTP sent to your email ID registered with WordPress.
  • Click on the Validate button.
  • Email OTP Login - click send OTP

    Now you must carefully store the backup codes provided to you. These codes will help you login when you become locked out of your account for any reason.

  • Click on the Finish button to finish it.
  • Email OTP Login - store the backup code
  • The user has successfully logged into the account.
  • Email OTP Login - Setup Security Questions

    Subsequent Login for user’s account through OTP Over Email

    Let’s see how user's subsequently login to their account after the configuration of OTP Over Email during the first login.

  • Go to the WordPress Login page and enter the user’s(in this case admin) credentials to login.
  • Email OTP Login - click login
  • Enter the 2FA code /2FA OTP sent to your email ID registered with WordPress.
  • Click on the Validate button.
  • Email OTP Login - enter 2fa code to verify
  • The admin has successfully logged into the account.
  • Email OTP Login - user login successful

2. OTP Over Email setup from plugin dashboard

    If you have choose to Skip Setup Wizard, here's an alternate way to setup OTP Over Email through the plugin dashboard.

    Email OTP Login - skipping setup wizard

    After clicking on the Skip Setup Wizard option, you will be redirected to the plugin dashbord i.e., the Login Settings tab of the two-factor authentication menu where you can enable 2FA for all the desired roles.

  • Enable 2FA for the all the roles for which you need to set 2FA.
  • Then, click on the Save Settings button.
  • Email OTP Login- for other roles

Steps for users to configure OTP Over Email

  • Go to the WordPress login page and enter the user’s login credentials.
  • Email OTP Login - enter password and login
  • Choose the “OTP Over Email” radio button. You are prompted to configure a two-factor method while logging in for the very first time.
  • Email OTP Login - Choose OTP Over Email
  • Enter the 2FA code /2FA OTP sent to your email ID registered with WordPress.
  • Click on the Validate button.
  • Email OTP Login - Enter mobile number

    Now you must carefully store the backup codes provided to you. These codes will help you login when you become locked out of your account for any reason.

  • Click on the Finish button to finish it.
  • Email OTP Login - store the backup code
  • The user has successfully logged into the account.
  • Email OTP Login - login successful

    Subsequent Login for user’s account through OTP Over Email

    Let’s see how user's subsequently login to their account after configuration of OTP Over Email during first login.

  • Enter your login credentials and click on the Login button.
  • Email OTP Login - click login
  • Enter the 2FA code/2FA OTP sent to your registered phone number via SMS.
  • Click on the Validate button.
  • Email OTP Login - enter 2fa code to verify
  • The user has successfully logged into the account.
  • Email OTP Authentication - logged in
Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com