The panel admin password is the most common target for brute force and phishing. Two-factor authentication in ISPmanager 6 closes this gap: even with a stolen password, an attacker cannot log in without a one-time code from an app on your phone.
Why enable 2FA in the control panel
ISPmanager 6 sits in front of the sites, databases, and mail of dozens of clients. Breaking into a single admin account grants access to the entire server at once. TOTP-based 2FA adds a second factor without external services and works even without internet access on the server.
Enable 2FA first for the built-in superuser and for reseller accounts — these are privileged accounts with access to other people's sites.
How to enable 2FA for the administrator
Go to "Settings" → "Users" → your account → the "Two-factor authentication" tab. The panel shows a QR code and a secret key as plain text in case the camera scanner is unavailable.
Scan the QR code in an authenticator app, enter the six-digit code to confirm, and save the set of backup codes — without them, recovering access after losing your phone is much harder.
Compatible apps for codes
| App | Platform | Note |
|---|---|---|
| Google Authenticator | Android, iOS | Simple offline code generator |
| Aegis Authenticator | Android | Encrypted backup of the code database |
| FreeOTP | Android, iOS | Open source, no account required |
Any app that supports the TOTP standard from RFC 6238 works; you are not tied to a specific vendor.
2FA for reseller users and clients
An administrator can make 2FA mandatory for all reseller-level accounts through a group security policy: "Settings" → "Security policies" → "Require two-factor authentication". Once the policy is on, the user sees a forced 2FA setup on the next login.
For clients with limited rights, two-factor protection is not mandatory, but it is worth recommending to anyone with access to databases and FTP. User access management is covered in the article about ISPmanager 6 user quotas and limits.
Lost access to the authenticator app
If the backup codes were not saved and the phone with the app is lost, logging in through the web interface is not possible — this is expected protective behavior. A server administrator can reset 2FA for a specific user through the console:
/usr/local/mgr5/sbin/mgrctl -m ispmgr user.edit elid=admin twofa=off
The command removes the second-factor requirement from the given account. After access is restored, set up 2FA again right away and check the login log for suspicious attempts:
grep 'auth' /usr/local/mgr5/var/ispmgr.log | tail -n 100
More on working with panel logs is in the article about ISPmanager 6 logs and diagnostics.
Summary: 2FA checklist
- Enable 2FA for the superuser and all reseller accounts
- Store backup codes in a separate protected place, not on the same server
- Set up a mandatory 2FA policy for privileged roles
- Confirm that resetting 2FA through the console requires an SSH key
- Periodically review the login log for password-guessing attempts