Home | Contact

How to Enable Two-Factor Authentication on Synology DSM

A Synology NAS often contains personal documents, business files, photographs, backups, and application data. A strong password protects the DSM administrator account, but it can still be exposed through phishing, reused credentials, malware, or a compromised device. Two-factor authentication adds a second requirement before DSM grants access.

Synology DSM supports several forms of multi-factor authentication, including time-based one-time passwords, approval prompts through Synology Secure SignIn, and selected hardware security keys. The exact wording and location of settings can vary slightly between DSM releases, but the setup process follows the same general pattern.

Before changing the setting, make sure you have access to your phone or security key and understand how account recovery works. A carefully configured second factor improves NAS security without making daily administration unnecessarily difficult.

Why Two-Factor Authentication Matters On DSM

Two-factor authentication, often abbreviated as 2FA or MFA, combines something you know with something you possess. Your DSM password is the first factor. A temporary code from an authenticator app, an approval in Secure SignIn, or a physical security key provides the second.

This protection is particularly valuable when DSM is reachable from the internet through a public IP address, reverse proxy, QuickConnect, or port forwarding. If an attacker obtains your password, the login should still fail without the additional factor. Two-factor authentication also helps protect Synology packages such as File Station, Synology Drive, Hyper Backup administration, and virtual machine management.

2FA does not replace secure configuration. It cannot prevent every threat, especially if an attacker gains control of an already trusted device or an active browser session. Use it with software updates, firewall rules, least-privilege accounts, and reliable backups.

Prepare Your Synology Account And Devices

Sign in to DSM using an account with administrative privileges. Update DSM and the Synology Secure SignIn application before beginning, particularly if your NAS has been running for a long time. Current software is more likely to display the latest security options and provide compatible recovery features.

Install an authenticator app on your phone if you plan to use time-based codes. Synology Secure SignIn is the natural choice for many DSM users, while apps such as Google Authenticator, Microsoft Authenticator, and Authy can support standard TOTP codes. Keep the phone’s date and time set automatically because inaccurate time can cause valid codes to be rejected.

Decide how you will recover access if your phone is lost, damaged, or replaced. Have a second trusted device available where possible, and store recovery codes offline in a password manager or another protected location. Do not save recovery codes in an unprotected text file on the NAS itself.

Choose A Second-Factor Method

DSM may present different choices depending on the version, account type, and installed Synology services. A time-based code is widely compatible and works without an internet connection after initial enrollment. Secure SignIn can make the process more convenient by sending an approval prompt or generating a verification code.

Hardware security keys offer strong phishing resistance because the key verifies the legitimate website or service before completing authentication. They can be an excellent choice for administrators, although a backup key is advisable. SMS-based verification is generally less desirable because phone numbers can be attacked through account takeover or SIM-swapping techniques.

Method Main Benefit Limitation Suitable Use
Authenticator app Works offline and is broadly supported Requires transferring the setup to a new phone Most home and small-office accounts
Synology Secure SignIn Convenient approval prompts and code support Depends on a compatible mobile device Frequent DSM administration
Hardware security key Strong protection against phishing Requires purchasing and carrying a key NAS administrators and business systems
SMS verification, where available Familiar and easy to understand Weaker protection than app or key-based methods Temporary or less sensitive access
Backup codes Useful during device loss or travel Each code should be protected and used only once Emergency account recovery

For a typical Synology owner, an authenticator app or Secure SignIn provides a good balance of security and convenience. Administrators who manage valuable business data should consider registering two hardware keys or combining a hardware key with a separate recovery method.

Enable Two-Factor Authentication In DSM

For an individual user, open DSM and select your account icon in the upper-right corner. Choose the personal account or profile settings, then open the security or account section and locate 2-factor authentication. In some DSM versions, the same option appears through Control Panel, User & Group, or an administrator account security page.

Select the option to enable two-factor authentication and follow the setup wizard. DSM normally displays a QR code for an authenticator application. Scan it with Secure SignIn or another compatible app, then enter the current six-digit code to confirm that enrollment works. If the app cannot scan the QR code, use DSM’s manual setup key.

When available, configure a second authentication method during the same process. For example, you might use Secure SignIn as the primary method and keep an authenticator application on a backup phone. Download or record the recovery codes when DSM offers them, and keep them in a secure offline location.

The change applies to the selected user rather than automatically protecting every account on the NAS. Each person who signs in to DSM should configure their own second factor. Shared administrator accounts should be avoided because they make auditing and recovery more difficult.

Verify The Login And Recovery Process

After enrollment, open a private browser window or sign out of DSM completely. Sign in again with the username and password, then complete the second-factor prompt. Testing the process immediately confirms that the QR code was registered correctly and that your phone can communicate with Secure SignIn when required.

If DSM offers trusted devices, use that feature selectively. A trusted computer reduces repeated prompts, but it also weakens protection if the computer is shared, stolen, or infected. Avoid marking public computers or devices used by multiple people as trusted.

Test recovery without disabling the protection on your main account. Confirm that the stored backup codes are readable and that a second registered device works. If you replace your phone, enroll the new device before removing the old one. Otherwise, you may need another administrator to reset the account’s 2FA settings.

Manage 2FA For Other NAS Users

Administrators can often require two-factor authentication for selected users or for all users through DSM’s security settings. Look under Control Panel, Security, and account-related options for an enforcement setting. The label can change between DSM releases, so use DSM Help if the option is not immediately visible.

Apply mandatory 2FA first to administrator accounts, users with access to shared folders containing sensitive information, and accounts that can manage packages or backup tasks. Standard users should also be enrolled, especially when they access DSM or Synology Drive remotely.

Before enforcing the requirement across an organization, provide users with setup instructions and a recovery procedure. An employee who loses a phone should have a defined way to prove their identity and regain access. Keep at least one protected emergency administrator account available, but do not use it for routine work or expose it unnecessarily.

Strengthen The Rest Of Your NAS Security

Two-factor authentication is most effective when it forms part of a wider Synology security policy. Review DSM login records, disable unused accounts, restrict administrative privileges, and remove old users promptly. Configure account lockout or automatic blocking for repeated failed logins where appropriate.

Use encrypted connections such as HTTPS and avoid exposing DSM directly to the public internet unless remote access is carefully designed. A VPN, properly configured reverse proxy, or Synology’s controlled remote-access features may be safer than forwarding multiple DSM service ports. Keep Hyper Backup or another backup system running so a stolen password or ransomware incident does not become permanent data loss.

Open DSM today, enroll your primary administrator account, and complete a fresh login test before extending the policy to other users. A few minutes spent configuring an authenticator app or security key can add a substantial barrier between an exposed password and the data stored on your Synology NAS.