Home / Blog Center / Tips & Tutorials /

How to Set Up Two-Factor Authentication on UGREEN NAS

#NAS storage: Tips & Tutorials

How to Set Up Two-Factor Authentication on UGREEN NAS

14/05/2025

UGOS Pro two-factor authentication requires your NAS account password and a six-digit one-time password generated by an OTP authenticator app. Microsoft Authenticator and Google Authenticator are supported examples. SMS codes and hardware security keys are not selectable factors in the UGOS Pro setup flow.

You will also add an emergency verification email during setup. That email provides a recovery path if your phone is lost or the OTP entry becomes unavailable.

How to Set Up 2FA on UGREEN NAS

Before You Enable 2FA on UGREEN NAS

Complete these preparations before opening the 2FA settings:

  • Install Microsoft Authenticator, Google Authenticator, or another OTP-compatible app on your phone.
  • Set the phone’s date and time to update automatically.
  • In UGOS Pro, open Control Panel > Time & Language > Time and enable Auto sync with time server.

  • Confirm that you can access a secure email account for emergency verification.
  • Keep your current UGOS Pro session open until you have tested the new login in another browser window.

OTP codes depend on the phone and NAS having matching time. Even a small clock difference can cause a valid six-digit code to be rejected.

If you are replacing your phone, use the authenticator app’s transfer, export, or restore function before erasing the old device. Test a UGREEN NAS login from the new phone before removing the OTP entry from the old one.

How to Enable 2FA on UGREEN NAS

Open Account Security

  1. Sign in to UGOS Pro with the account you want to protect.
  2. Click the user icon in the upper-right corner of the desktop.
  3. Select your username to open Account Settings.
  4. Select Account Security from the left menu.
  5. Find Two-Factor Authentication and begin the setup.
  6. Enter the current account password when UGOS Pro asks you to verify your identity.
Enable 2FA on UGREEN NAS

Two-factor authentication is configured for the account currently signed in. Other NAS users must enable it separately on their own accounts.

Bind an OTP Authenticator App

In the Two-Factor Authentication Setup window, select App Installed, Next. UGOS Pro will display a QR code.

Open the authenticator app on your phone and add a new account:

  • In Microsoft Authenticator, select Add Account, then Scan QR Code.
  • In Google Authenticator, select the option to add an account by scanning a QR code.
In Microsoft Authenticator, select Add Account

Scan the code displayed by UGOS Pro. The authenticator will create an entry for the UGREEN NAS account and begin generating six-digit OTP codes.

Treat the QR code as a password. Anyone who obtains it can configure another authenticator and generate valid codes. Do not photograph, share, or publish a screenshot containing the real QR code.

Verify the Six-Digit OTP

Return to the UGOS Pro setup window and enter the six-digit code currently displayed in the authenticator app. Select Next.

If the code is close to changing, wait for the next one before submitting it. This reduces the chance that the code will expire during verification.

Add an Emergency Verification Email

Enter an email address that you control and select Get Verification Code. Retrieve the code from that inbox, enter it in UGOS Pro, and submit it to complete the setup.

Add an Emergency Verification Email

This email is a recovery method. It is not the code source used during a normal 2FA login.

UGOS Pro does not issue a separate list of one-time backup codes during 2FA enrollment. Recovery instead relies on the emergency verification email, an existing trusted device, another administrator, or the device-reset procedure. That makes the security of the emergency email especially important.

Never reuse the NAS password for the emergency email account. If both accounts share the same credentials, compromising one password can also compromise the recovery path and weaken the protection provided by 2FA.

Protect the email account with its own MFA. Review its recovery phone numbers and secondary email addresses as well, because those routes may also provide access to the inbox.

Test the New Login

Do not immediately close your working UGOS Pro session.

Open a private browsing window or use another trusted device, then sign in with the same NAS account:

  1. Enter the account name and password.
  2. Open the authenticator app.
  3. Enter the current six-digit OTP.
  4. Confirm that UGOS Pro completes the login.

Keep the original session open until this test succeeds. If the test fails, you can correct the account, time, or OTP settings without locking yourself out.

Where Does the UGREEN Verification Code Come From?

UGREEN NAS can request different verification codes for different actions. The screen you are viewing determines where to find the code.

When the code is requested Where the code comes from
After entering your NAS password during a 2FA login Microsoft Authenticator, Google Authenticator, or the OTP app bound during setup
While adding or verifying the emergency email The emergency email inbox
When recovering access because the OTP app is unavailable The emergency email inbox
During UGREEN Account registration or account verification The email address or phone number associated with the UGREEN Account

During a normal UGOS Pro 2FA login, do not wait for an email or text message. Open the authenticator app and use the current six-digit code shown for the NAS account.

What Does UGREEN NAS 2FA Protect?

Two-factor authentication protects supported UGOS Pro sign-ins for the account on which it is enabled. A stolen password alone is no longer enough to complete that login.

It does not add an OTP prompt to every service connected to the NAS. SMB, NFS, SSH, WebDAV, Docker applications, and third-party services use their own authentication and access controls. For example, a computer connecting to an SMB shared folder signs in with the relevant NAS username and password rather than stopping to request the UGOS Pro OTP.

Use separate security controls for those services:

  • Disable services you do not use.
  • Keep SMB and NFS off the public internet.
  • Restrict SSH to trusted networks and disable it when administrative work is complete.
  • Give Docker applications their own strong credentials.
  • Limit every account to the folders and permissions it actually needs.

If you need to reach the NAS while away from home, enable 2FA before following our guide to setting up remote access for UGREEN NAS.

Be Careful with Trusted Devices

The UGOS Pro login screen includes a Trust this device option. Once a device is trusted, future sign-ins on it can skip the OTP step.

Use this option only on a private computer or phone that you control. Do not trust a public, shared, borrowed, or workplace device.

To review trusted devices:

  1. Open Account Settings.
  2. Select Account Security.
  3. Open Manage Trusted Devices.
  4. Verify your account password.
  5. Revoke any device that has been lost, sold, shared, or is no longer used.

A trusted device weakens the protection offered by the second factor if someone else gains access to that device.

Why Is My UGREEN OTP Code Not Working?

Problem Likely cause What to do
Every code is rejected The NAS or phone clock is incorrect Enable automatic time synchronization on both devices
An isolated NAS rejects every code It cannot reach a valid time source Configure a reachable NTP server inside the local network
One code fails near the end of its cycle The code expired while being entered Wait for the next code and submit it promptly
The app shows several UGREEN entries The QR code was scanned more than once Identify the newest working entry and remove obsolete duplicates only after testing
The code belongs to another NAS or account The wrong authenticator entry is selected Check the account label before entering the code
Codes stopped working after changing NAS time settings The NAS clock is no longer synchronized Restore automatic time-server synchronization
The OTP entry was removed from the phone The authenticator no longer has the bound secret Recover access through the emergency email, a trusted device, or another administrator
The phone was replaced The OTP account was not transferred Use a recovery method and bind the authenticator on the new phone

Do not repeatedly rescan the QR code during troubleshooting. Each new enrollment can create another authenticator entry, making it harder to identify which code is valid.

How to Recover Access If Your Phone Is Lost

UGOS Pro provides four recovery paths. Use them in the following order, starting with the option that changes the least.

Use the Emergency Verification Email

On the Enter Verification Code screen, select Unable to Verify through OTP.

UGOS Pro will send a verification code to the emergency email added during 2FA setup. Enter that code on the login screen. After signing in, open Account Security and either disable 2FA or bind a new authenticator app.

If the message does not arrive, check the spam folder and confirm that you are viewing the correct emergency email account.

Use an Existing Trusted Device

A previously trusted device can sign in without requesting the OTP.

From that device:

  1. Open UGOS Pro.
  2. Click the user icon and select your username.
  3. Go to Account Settings > Account Security.
  4. Disable Two-Factor Authentication.
  5. Enter the account password to confirm the change.
  6. Enable 2FA again and bind the authenticator on the replacement phone.

Do this before wiping, selling, or giving away the trusted device.

Ask Another Administrator to Disable 2FA

If the NAS has another working administrator account, that administrator can disable 2FA for the affected user:

  1. Sign in with the other administrator account.
  2. Open Control Panel > User Management.
  3. Locate the locked account.
  4. Open the account’s ... menu and select Edit.
  5. Find the Two-Factor Authentication setting and disable it.
  6. Save the change.

The affected user can then sign in with the account password and configure 2FA again.

This is one reason a NAS used for a family or business should not depend on a single shared administrator account.

Reset the Device as a Last Resort

Use the physical reset method only when all of the following are true:

  • The OTP app is unavailable.
  • The emergency email cannot be used.
  • No trusted device remains.
  • No other administrator can restore access.

Before beginning, keep the NAS connected only to a trusted local network. Do not leave the management interface, UGREENlink, DDNS, or another remote-access path exposed while the emergency administrator account is available.

Press and hold the NAS Reset button for five seconds. Release it after the device beeps, then wait for the NAS to restart. Sign in using the temporary emergency administrator account, set a new administrator password immediately, and then restore access to the original account.

Review the user list, trusted devices, remote-access settings, and account activity before reconnecting the NAS to remote services. Reconfigure 2FA only after the new password and recovery email are secured.

A reset can return some settings to their defaults. Back up important data and record the current configuration before using this recovery path whenever possible.

Protect Every Account That Can Administer the NAS

Enabling 2FA on one administrator account does not protect every other account.

For a shared NAS:

  • Give each administrator a separate account.
  • Enable 2FA on every account with administrative privileges.
  • Use Standard User accounts for everyday file access.
  • Do not share an administrator password or one OTP enrollment among several people.
  • Protect each emergency verification email with its own MFA.
  • Review Account Activity after unexpected verification prompts.
  • Remove inactive users and revoke old trusted devices.

For a household with several users, follow the complete workflow for organizing family accounts, personal folders, and shared data on UGREEN NAS.

Two-factor authentication reduces the value of a stolen password, but it remains one part of the NAS security plan. Continue with our guide to securing your UGREEN NAS and home network to review remote access, firewall rules, account permissions, exposed services, updates, alerts, and independent backups.

Quick Navigation
Top Picks for You
UGREEN NASync DXP2800
UGREEN NASync DXP2800

$369.99 $439.99

Learn More
$70 OFF
flag
Related Reads
Connect UGREEN NAS to Mac: Finder and Time Machine Setup
Connect UGREEN NAS to Mac: Finder and Time Machine Setup
27/11/2024