Realsmart Help

All guides / Users

Require MFA for staff and students

You can require multi-factor authentication (MFA) at sign-in with two independent, school-wide settings — one for staff, one for students. They work the same way and share the exact same mechanism; the only difference is who they apply to.

Turning it on

In School settings → Password, under Two-factor authentication (2FA):

  • Enable 2FA for all staff — applies to every non-learner (admin, mentor, governor, observer, Ofsted).
  • Enable 2FA for all students — applies to every learner in the school, from Reception through Year 13. There's no age-based exception, so think about whether that's right for your youngest pupils before turning it on.

Turn on either, both, or neither — they don't depend on each other.

These two used to be labelled "Enable 2FA for new staff/students". They're the same settings — renamed because they have always applied to existing members as well as new ones, as the next section explains.

School settings Password tab showing the Enable 2FA toggles for staff and students together

When a setting is on:

  • Every member in that group is set to require MFA.
  • Existing members are updated straight away — not just new ones.
  • Anyone added later is covered automatically while the setting stays on.
  • Members outside that group are never affected — turning on the staff setting never touches learners, and vice versa.

One user at a time

You don't need a school-wide setting to use 2FA. On any user's edit page, the Security tab has a Require 2FA switch for that person alone, a badge showing whether they've set up an authenticator yet, and a Reset authenticator button for when they've lost their phone.

The school-wide setting outranks the per-user switch: while a setting above is on, the switch is locked on for everyone it covers and can't be turned off per user. For the one person who genuinely can't use MFA, use the exemption described below instead of turning the school setting off — turning it off doesn't turn 2FA off for anyone; it only stops requiring it for people added later.

What it doesn't change

This controls the MFA requirement on each account. The actual MFA prompt and enrolment happen at sign-in — a member who hasn't set up MFA yet is walked through it when they next sign in, rather than being locked out. This matters most for students: a child who was locked out couldn't recover their own access the way a member of staff usually can, so neither setting ever works that way.

Trusted IP addresses (on the same Password tab, under the two toggles) is a separate, network-level exception: sign-ins from those addresses skip the 2FA step altogether, whoever is signing in. Enter addresses separated by commas. It applies to both settings alike and is unrelated to the per-person exemptions below.

Both settings are per-school and admin-only, and every change is logged in the audit trail.

Exempt one person

Sometimes one person genuinely can't use MFA even though their group requires it — no personal device, a disability an authenticator app doesn't accommodate, or a shared/break-glass account. Rather than turning the school-wide setting off for everyone, admins can exempt just that one member.

One user, from their profile: open the user's edit page, go to the Security tab, and in the Two-factor authentication card use Exempt from MFA (it appears only while the school requires MFA for their role). The badge shows Exempt, the switch stays locked, and the button reads Remove MFA exemption once they're exempt, so you can reverse it the same way.

Several at once: select the users in the Users list, open Password actions, and choose Exempt from MFA or Remove MFA exemption.

The whole list, from School settings: the Exempt users list under the 2FA toggles on School settings → Password shows everyone currently exempt in this school, as a row of pills. Type a name, username or MIS id into the search box and pick someone to add them; select the × on a pill to remove that person's exemption. Each add or remove applies straight away — it doesn't wait for Save password settings. This is the same exemption as the two routes above (one list, three places to manage it), so a person exempted from their profile appears here, and someone removed here shows as no longer exempt on their profile.

What exemption does:

  • The member's MFA requirement is switched off immediately — they won't be asked for MFA at sign-in even though the school-wide setting for their group (staff or students) is on.
  • It's per-user and reversible: removing the exemption re-applies the school's requirement for that person straight away, the same way turning the school-wide setting on does for everyone else.
  • The overnight sync respects it — an exempt member is never swept back into "must use MFA" by the nightly reconciliation, only by an admin explicitly removing the exemption.
  • Exemption is admin-only, and both setting and removing it are logged in the audit trail.