Hi @kloproterra,
You’ve identified a genuine, well-known limitation of this plugin. The Two Factor plugin currently works on a voluntary, per-user basis — each user must opt in to configure a second factor themselves. There is no built-in way for a site administrator to require that users in certain roles have 2FA configured before they can access the site. This gap is consistently the most-requested missing feature in the plugin.
There is an open GitHub issue (#846) tracking role-based enforcement as a planned feature, but it isn’t in the plugin yet.
Sorry the plugin doesn’t meet your use case in its current state — hopefully the enforcement feature lands in a future release.
Hey @kloproterra — You may be interested in a companion plugin I created to require and immediately enforce two-factor (emailed codes) for all users: https://github.com/dknauss/Require-Email-2FA
Read the docs to learn how to limit the enforcement scope by user role, etc., and take note of the checklist for rolling out a policy like this. While it is a very good idea to enforce 2FA as a matter of policy, if you do it for a lot of users all at once, there will be problems and potentially a big spike in support needs. That is not the fault of WordPress or any plugins. Even if you warn people in advance and ensure email is configured for effective delivery, there will be complaints and lockouts.
Please reconsider your 1-star review for two-factor: it is a community-supported plugin that deliberately does not (yet) offer the features you are looking for. You will find other 2FA plugins (at least in their free versions) have approximately the same limitation probably because a 2FA policy enforcement feature is a guaranteed source of negative reviews and noisy support tickets from people who blame the plugin for the inherent challenges of a mandatory 2FA policy.
Hello,
Thank you for the follow up, I really appreciate it.
I was able to use part of this plugin and added an extra part myself to store a boolean in user meta. Basically, once 2FA is set it cannot be unset. PHP is not my language so I don’t want to promote it as secure when I can’t verify, especially after it was tweaked using Claude Code (full admission), and I’m aware my solution wouldn’t cover any site with REST API auth; I just don’t have the knowledge to contribute here.
I recognise what a 1-star review does to a community-supported plugin, however the description of the plugin states “The Two-Factor plugin adds an extra layer of security to your WordPress login by requiring users to provide a second form of authentication in addition to their password.” From my experience this is false. Until there is an enforcement mechanism, I think my position is fair. Alternatively, it provides user-elective protection, not site-policy.
Kyle
You have a point, but it is a very nit-picking technical point that doesn’t merit ignoring everything else about two-factor.
Add the context or necessary condition for the outcome you want — “When enabled by users…” — and the claim the plugin makes is entirely accurate: “The Two-Factor plugin adds an extra layer of security to your WordPress login by requiring users to provide a second form of authentication in addition to their password.”
It’s not very complicated to add an enforcement mechanism; what is challenging is actually enforcing it on live sites with real users. Even a role scoped policy model is probably not a good idea for two-factor because it is quite rigid in its assumptions. Some sites and users need an opt-in, or a nudge or grace period for mandatory opt-in. At the same time on the same site, 2FA might be a hard requirement for certain users and roles.
Another example (fork of this plugin) to consider for personal use: https://github.com/humanmade/two-factor/pull/1