---
title: "How to Configure Security Policies in WHM"
description: "WebHost Manager (WHM) includes many tools to help you secure your cPanel server. Steps such as limiting logins by IP address, enabling two-factor authentication (TFA), and setting password strength..."
url: https://www.inmotionhosting.com/support/edu/whm/how-to-configure-security-policies-in-whm/
date: 2019-05-29
modified: 2022-05-31
author: "InMotion Hosting Contributor"
categories: ["WebHost Manager (WHM)"]
type: post
lang: en
---

# How to Configure Security Policies in WHM

[WebHost Manager (WHM)](https://www.inmotionhosting.com/support/edu/whm/cpanel-vs-whm/) includes many tools to help you secure your cPanel server. Steps such as limiting logins by IP address, enabling two-factor authentication (TFA), and setting password strength and age limits can greatly increase the security of your server. In this guide, we will show you how to configure the security policies of your VPS or dedicated server.

**Scalable VPS Infrastructure, Fully Managed**

When shared hosting can’t handle your traffic, VPS delivers dedicated resources that scale with demand. Our team manages the technical complexity while you manage your business.

![check mark](https://design.inmotionhosting.com/assets/icons/standard/check-blue.svg)NVMe Storage    ![check mark](https://design.inmotionhosting.com/assets/icons/standard/check-blue.svg)High-Availability    ![check mark](https://design.inmotionhosting.com/assets/icons/standard/check-blue.svg)Ironclad Security    ![check mark](https://design.inmotionhosting.com/assets/icons/standard/check-blue.svg)Premium Support

[VPS Hosting](https://www.inmotionhosting.com/vps-hosting?mktgp=t&irgwc=1&affiliates=5001860&utm_campaign=Jumbotron&utm_source=supportcenter&utm_medium=cta&utm_term=vps-cta2)

## Configure Security Policies

1. [Log into WHM](https://www.inmotionhosting.com/support/edu/whm/log-into-whm/) as the ‘[root](https://www.inmotionhosting.com/support/amp/obtain-root-access/)‘ user.  
2. Type ‘policies’ in the search field.  
3. Click the **Configure Security Policies** link under the *Security Center* section.  
4. You can then enable “Security Policy Items”. Choose from the following options:   Limit logins to verified IP addresses Two-Factor Authentication: Google Authenticator Password Strength (selecting this will direct you to the [Password Strength Configuration](https://www.inmotionhosting.com/support/edu/whm/whm-password-configuration/) page) Password Age (selecting this will allow you to enter a Maximum Password Age)
5. There is also a section where you can set **Security Policy Extensions**, but cPanel warns “*do not enable these extensions unless you have an in-depth understanding of your remote API usage and DNS cluster configuration.*” If you still want to adjust the settings you can enable security policies for the following: [API requests](https://docs.cpanel.net/cpanel/advanced/api-shell-for-cpanel/) [DNS Cluster Requests](https://www.inmotionhosting.com/support/product-guides/vps-hosting/dnssec-managed-vps-dedicated/)  
6. After choosing your security policy settings click the **Save** button. You are finished when you see a message stating “*Security Policies Configured*.”

![cPanel Security Advisor can offer advice to compliment your new security policies](https://www.inmotionhosting.com/support/wp-content/uploads/2016/06/dedicated-hosting_basic-security_cpanel-security-advisor-300x145.png)

Congratulations, now you know how to configure security policies in WHM! Test your security posture with the [Security Advisor](https://www.inmotionhosting.com/support/edu/cpanel/how-to-scan-your-server-with-the-cpanel-security-advisor/) for more ways to secure your server.

Learn more about cPanel security with our [Managed VPS Hosting Product Guide](https://www.inmotionhosting.com/support/product-guides/vps-hosting/).

![How to Enable Two-factor Authentication in WHM](https://i.ytimg.com/vi_webp/G3VSm6Jak1w/maxresdefault.webp)

*We recommend our video on How to Enable Two-factor Authentication in WHM.*
