# Look after your own account from your profile

Every user can set up two-factor, add passkeys and see where they are signed in from their WordPress profile, or from a store’s My Account page.

BetterShield’s own screens are for people who manage the site. Everyone else, from authors to store customers, looks after their own sign-in from their WordPress **Profile**. BetterShield adds three sections there, below WordPress’s own: **Two-factor sign-in**, **Passkeys** and **Where you are signed in**. Administrators see the same three on their own profile.

## Two-factor sign-in

Anyone can turn on two-factor for their own account here: press **Set up two-factor**, scan the code with an authenticator app or type the **Manual entry key**, enter the **Code from the app**, press **Confirm code**, then store the ten backup codes and confirm. The steps are the same as on **Protect › Two-Factor**; see [Two-factor and passkeys](/docs/two-factor-and-passkeys/).

Once it is on, the section shows how many backup codes are left. When three or fewer remain, it suggests issuing a new set while you still can. **Issue new backup codes** asks for a **Code from the app, or a backup code** first.

## Passkeys

Type **Name this device**, such as Work laptop, and press **Add a passkey**, then confirm on your device. Each passkey is listed with **Remove**. An account holds up to ten, and passkeys need HTTPS. If your role signs in with a passkey only, the section says so, and that your password no longer signs you in.

## Where you are signed in

A table of every device signed in to your account, most recent first:

| Column | What it shows |
|---|---|
| **Device** | The browser it signed in from, or **An unnamed device**. The one you are using is marked as this device. |
| **Network** | The network it came from, such as 203.0.113.0/24, never the full address, or **Not recorded**. |
| **Last active** | When that session was last used. |

- **This was not me** ends one session straight away. It is not shown beside the device you are using.
- **Sign out everywhere except this device** ends all the others at once.

If you do not recognize a device, end it and change your password. Each ending is recorded in the activity log as **Signed out of a device**.

On multisite, a session covers every site of the network, so ending one here ends it everywhere. Where another plugin has replaced how WordPress stores sessions, **This was not me** is not offered, and **Sign out everywhere except this device** still works.

## On a store’s My Account page

WooCommerce keeps customers out of the dashboard, profile included. For them, BetterShield adds a **Sign-in security** tab to **My Account** with the same three sections. Links that would point to the profile point there instead.

## Notices on your dashboard

If the site requires two-factor of your role, a notice on your dashboard pages says how long you have to set it up. With BetterShield Ultra’s [Sign-in policies](/docs/sign-in-policies/), a role can also be reminded to add a passkey.

## What an administrator sees on your profile

Opening someone else’s account under **Users**, an administrator sees only whether it uses two-factor. If it does, **Turn off two-factor for this account** removes it, for someone who lost both their phone and their backup codes. Nobody can set up two-factor or add a passkey for another person, and their sessions are ended from **Protect › Login & Access** (**Who is signed in**) instead.

## Related

- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Login & Access](/docs/login-and-access/)
- [Locked out](/docs/locked-out/)
- [Privacy and personal data](/docs/privacy-and-personal-data/)
