+254725682556 +254725052660 info@ziprof.co.ke
Client Area

Security

What to Do If You Lose Your Two-Factor Authentication Device for Your Control Panel

If you turned on two-factor authentication for your control panel and then lost, reset, or replaced the phone running your authenticator app, you won't be able to generate the one-time code your login screen asks for. This doesn't mean you're locked out for good: you can usually get back in with a backup code, and if you don't have one, ZIPROF support can disable two-factor authentication on your account once your identity is verified.

Why This Happens

Two-factor authentication relies on a code generated on a specific device, usually an app like Google Authenticator or Authy. If that device is lost, wiped, replaced, or the app is uninstalled without transferring your accounts first, the codes it was generating are gone with it. Your control panel has no way to know this happened, so it keeps asking for a code you can no longer produce.

Step 1: Check for a Backup Code First

When you first set up two-factor authentication, many setups show you a set of one-time backup codes alongside the QR code. These are meant exactly for this situation.

In cPanel

  • Check any notes, password manager entries, or screenshots you saved when you first enabled two-factor authentication in cPanel's Security > Two-Factor Authentication section.
  • If you have a backup code, enter it in place of the six-digit code on the login screen where prompted.
  • Once logged in, go straight back to Two-Factor Authentication, remove the old configuration, and set it up again with your current device.

In DirectAdmin

  • Check the same way for any backup codes saved when you enabled two-factor authentication under your DirectAdmin account settings.
  • If one works, log in with it, then open the two-factor authentication settings again to reconfigure it with your current device.
Each backup code normally works only once. After you use one to log back in, generate or save a fresh set (or simply reconfigure two-factor authentication) so you have a working backup again.

Step 2: No Backup Code? Contact ZIPROF Support

If you don't have a backup code, you can't remove two-factor authentication yourself from the login screen, that's the whole point of the feature. You'll need ZIPROF support to disable it on the account before you can log in again.

  1. Open a support ticket from your ZIPROF client area, or reply to a previous ZIPROF email if you can't log in to the client area either.
  2. Explain that you've lost access to your two-factor authentication device and need it disabled so you can log back into your control panel.
  3. Be ready to confirm details tied to your account, such as your domain name, your invoice number, or other account information, so support can verify it's really you.
  4. Once support disables two-factor authentication on the account, log in with just your regular username and password.
For your account's security, ZIPROF support will always verify your identity before disabling two-factor authentication on your account. Don't be surprised if you're asked to confirm details only the account owner would know, this step protects you from someone else trying to use the same excuse to get in.

Step 3: Re-Enable Two-Factor Authentication Right Away

Once you're back in, don't leave two-factor authentication turned off. Set it up again immediately with your current phone, and this time save the backup codes somewhere you'll actually be able to find later, such as a password manager or a printed copy kept somewhere safe, not just a screenshot on the same phone you might lose again.

Avoiding This Next Time

  • Save backup codes outside your phone, in a password manager or another secure location.
  • If your authenticator app supports encrypted cloud backup or multi-device sync, turn it on before you need it.
  • Before wiping, replacing, or selling a phone, transfer or re-register your two-factor authentication entries first.

For the setup steps themselves, see How to Enable Two-Factor Authentication for Your Control Panel Login. If you need to reach support to get this sorted, see How to Open and Track a Support Ticket in Your ZIPROF Client Area.