Before you begin, make a full backup of your WordPress site.
Whitelist your IP address in the Dashboard area.
Click on the Settings Tab at the top menu area.
Check the option to “Allow iThemes Security Pro to write to wp-config.php.“
Verify that your email address is correct.
Check the box next to “Send digest email” to cut down on notification emails.
Click Save All Settings button at the base of the Global Settings section.
In the 404 Detection section, check the box next to “Enable 404 detection.“
Click Save All Settings button at the base of the 404 Detection section.
In the Banned Users section, check the box next to “Enable HackRepair.com’s blacklist feature.“
Check the box next to “Enable ban users.“
Click Save All Settings button at the base of the Banned Users section.
In the Brute Force Protection section, enter your email address in the field next to “Get your iThemes Brute Force Protection API Key.“
Check the box next to “Enable local brute force protection.“
Click Save All Settings button at the base of the Brute Force Protection section.
In the Strong Passwords section, click the box next to “Enable strong password enforcement.“
Click Save All Settings button at the base of the Strong Passwords section.
Check ALL THE BOXES in the System Tweaks section.
Click Save All Settings button at the base of the System Tweaks section.
In the WordPress Tweaks section --
Also in the WordPress Tweaks section, set the drop-down box in the XML-RPC section to Completely Disable XML-RPC.
Click Save All Settings button at the base of the WordPress Tweaks section.
Click on the top Pro tab and in the Malware Scan Scheduling section, check the box next to “Enable scheduled malware scanning.“
Make sure the “Email Contacts” are going to the people you want to receive alert notifications.
Click Save All Changes button at the base of the Malware Scan Scheduling section.
In the Two-Factor Authentication section, check one or more of the boxes in the “Enable Two-Factor Providers” section.
Follow the video to see the full demonstration on how to work with two-factor authentication.
Click the Save All Changes button at the base of the Two-Factor Authentication section.
Check to make sure your WordPress site is working as desired.
Make a new full backup of your WordPress site.