Docs / Getting started

Guided setup

Review login limits, two-factor authentication, hardening and alerts before applying your setup.

All documentation

The first-run wizard helps you configure FluentAuth in a short sequence. It explains each choice and presents a review before applying settings. Skipping the wizard does not save its proposed configuration. Everything it applies remains editable in ordinary settings.

What you choose

  • Login limits: how many failed attempts an address can make within a time window.
  • Two-factor authentication: protection for the roles that need it.
  • Hardening: WordPress capabilities and public endpoints to restrict.
  • Alerts: which login events should email you.
  • Connection: whether to connect the optional scan alerts service.

Review before applying

Read the final summary. Keep application passwords available if your integrations need them, and check your profile email before enabling email verification at login. Do not require a device method before you have a working enrolment and recovery route.

Connecting the alerts service is optional. It shares site identification, extension versions and scan-result paths as explained on the connection screen; file contents are not uploaded. You can still run manual file checks without connecting.

After setup

Follow First-day setup to test a separate login, check the activity log, review findings and configure any member-facing sign-in options. You can revisit choices under Settings → General Settings at any time.