Two-factor authentication (2FA) is one of the best ways to protect your account from the risk of account takeover. Cloudflare has offered phishing resistant 2FA options including hardware based keys (for example, a Yubikey) and app based TOTP (time-based one-time password) options which use apps like Google or Microsoft’s Authenticator app. Unfortunately, while these solutions are very secure, they can be lost if you misplace the hardware based key, or lose the phone which includes that app. The result is that users sometimes get locked out of their accounts and need to contact support.
Today, we are announcing the addition of email as a 2FA factor for all Cloudflare accounts. Email 2FA is in wide use across the industry as a least common denominator for 2FA because it is low friction, loss resistant, and still improves security over username/password login only. We also know that most commercial email providers already require 2FA, so your email address is usually well protected already.
You can now enable email 2FA on the Cloudflare dashboard:
- Go to Profile at the top right corner.
- Select Authentication.
- Under Two-Factor Authentication, select Set up.
Sign-in security best practices
Cloudflare is critical infrastructure, and you should protect it as such. Review the following best practices and make sure you are doing your part to secure your account:
- Use a unique password for every website, including Cloudflare, and store it in a password manager like 1Password or Keeper. These services are cross-platform and simplify the process of managing secure passwords.
- Use 2FA to make it harder for an attacker to get into your account in the event your password is leaked.
- Store your backup codes securely. A password manager is the best place since it keeps the backup codes encrypted, but you can also print them and put them somewhere safe in your home.
- If you use an app to manage your 2FA keys, enable cloud backup, so that you don’t lose your keys in the event you lose your phone.
- If you use a custom email domain to sign in, configure SSO.
- If you use a public email domain like Gmail or Hotmail, you can also use social login with Apple, GitHub, or Google to sign in.
- If you manage a Cloudflare account for work:
- Have at least two administrators in case one of them unexpectedly leaves your company.
- Use SCIM to automate permissions management for members in your Cloudflare account.
Source: Cloudflare
Latest Posts
- (Updated) Action required: Update Teams Rooms app to maintain PowerPoint Live functionality [MC1332812]
![(Updated) Action required: Update Teams Rooms app to maintain PowerPoint Live functionality [MC1332812] 2 pexels punttim 139764](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Transitioning Teams Android Device Management from Teams admin Center to the Teams Rooms Pro Management portal [MC1227622]
![(Updated) Transitioning Teams Android Device Management from Teams admin Center to the Teams Rooms Pro Management portal [MC1227622] 3 pexels merlin 11167639](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Interact with your favorite apps on Teams using Slash ( / ) Commands [MC1319214]
![(Updated) Interact with your favorite apps on Teams using Slash ( / ) Commands [MC1319214] 4 street art 9614300 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Rewrite with Microsoft 365 Copilot Chat coming soon to Edge for Business users [MC1146821]
![(Updated) Rewrite with Microsoft 365 Copilot Chat coming soon to Edge for Business users [MC1146821] 5 pexels pixabay 434645](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![(Updated) Action required: Update Teams Rooms app to maintain PowerPoint Live functionality [MC1332812] 2 pexels punttim 139764](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-punttim-139764-150x150.webp)
![(Updated) Transitioning Teams Android Device Management from Teams admin Center to the Teams Rooms Pro Management portal [MC1227622] 3 pexels merlin 11167639](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-merlin-11167639-150x150.webp)
![(Updated) Interact with your favorite apps on Teams using Slash ( / ) Commands [MC1319214] 4 street art 9614300 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/street-art-9614300_1920-150x150.webp)
![(Updated) Rewrite with Microsoft 365 Copilot Chat coming soon to Edge for Business users [MC1146821] 5 pexels pixabay 434645](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-434645-150x150.webp)
