Skip to main content

Two-Factor Authentication and Hardening the Proxmox VE Panel

Proxmox VE · 29.09.2026

Why the Proxmox VE Panel Needs Two-Factor Protection

The Proxmox VE web interface on port 8006 gives full control over virtual machines: start, stop, console, disks, and backups. One compromised administrator password without a second factor means access to the whole infrastructure, not just one service.

Two-factor authentication (2FA) requires a one-time code or a hardware key confirmation after the password. Even if the password leaks through phishing or another site's breach, logging into the panel without the second factor is not possible.

Which 2FA Methods Proxmox VE Supports

Proxmox VE supports several second-factor options: one-time TOTP codes from an authenticator app, hardware and platform WebAuthn keys, and one-time passwords from a pre-generated list (recovery keys).

MethodWhat is neededWhen it fits
TOTPan authenticator app on a phonebaseline protection for every user
WebAuthna USB key or device biometricsadministrators with full access
Recovery keysa printed list of one-time codesa backup for a lost phone

How to Enable TOTP for a User

Setup is done by the user themselves in Datacenter → Permissions → Two Factor or through the personal profile in the top-right corner of the panel.

# add a TOTP factor for a user via the console
pveum user tfa add ivan@pve --type totp

After running the command or confirming in the web interface, Proxmox VE shows a QR code: it is scanned with an app such as Google Authenticator or Aegis, then the first generated code is entered to confirm the binding. From that point on, every login after the password will show an extra field for the code.

Backup Codes and What to Do if a Phone Is Lost

When setting up TOTP, Proxmox VE offers to save a set of one-time backup codes. Each code works once and can be used instead of TOTP if the phone with the authenticator app is unavailable.

  • Print or store the backup codes separately from the phone that holds the app.
  • If the codes run out and the phone is lost, only an administrator with the PVEAdmin role can restore access, through Permissions → Two Factor, by removing the factor from the locked-out user.
  • After recovery, set up TOTP again right away on the new device.

This is why a second administrator should always have a separate account with 2FA configured — the correct distribution of such roles is described in the article on users and ACLs.

WebAuthn Keys for Administrators

For accounts with the PVEAdmin role, it makes sense to use WebAuthn instead of or in addition to TOTP: a physical key cannot be intercepted by phishing, and the binding is tied to the panel's specific domain. The key is registered in the same Two Factor section with the Add → WebAuthn button, after which the browser asks to touch the key or confirm with a fingerprint.

WebAuthn does not replace the password — it is added on top as a second factor. The combination "password plus hardware key" practically rules out remote compromise of an administrator account.

Extra Protection: Port, Attempt Limits, and Fail2ban

2FA reduces the damage from a leaked password, but it does not stop password brute-forcing on port 8006 itself. It is also worth restricting access to the port with the Proxmox VE firewall, allowing login only from trusted addresses or through a VPN.

# fail2ban for the Proxmox web interface
apt install fail2ban
systemctl enable --now fail2ban
fail2ban-client status proxmox

Starting with modern Proxmox VE versions, a ready-made fail2ban jail is already included, blocking an IP address after several failed login attempts to the panel. It can be turned on with the single command above, with no manual filter setup needed.

Checklist for Protecting the Proxmox VE Web Interface

  • Every administrator has TOTP or WebAuthn enabled.
  • Backup codes are stored in a safe place separate from the phone.
  • Access to port 8006 is restricted by a firewall or a VPN.
  • Fail2ban is enabled to block password brute-forcing.
  • API tokens for automation are issued separately from the user's password.

This set of measures protects the management panel from typical attacks and makes compromising a single password insufficient for gaining access to the infrastructure.

← Back to Knowledge Base Ask Support