Realsmart Help

← Realsmart Help

Require MFA for staff and students

Require MFA for staff and students

You can require multi-factor authentication (MFA) at sign-in with two independent, school-wide settings — one for staff, one for students. They work the same way and share the exact same mechanism; the only difference is who they apply to.

Turning it on {#step-1}

In School settings → Password, under Two-factor authentication (2FA):

  • Enable 2FA for new staff — applies to every non-learner (admin, mentor, governor, observer, Ofsted).
  • Enable 2FA for new students — applies to every learner in the school, from Reception through Year 13. There's no age-based exception, so think about whether that's right for your youngest pupils before turning it on.

Turn on either, both, or neither — they don't depend on each other.

School settings Password tab showing the Enable 2FA toggles for staff and students together

When a setting is on:

  • Every member in that group is set to require MFA.
  • Existing members are updated straight away — not just new ones.
  • Anyone added later is covered automatically while the setting stays on.
  • Members outside that group are never affected — turning on the staff setting never touches learners, and vice versa.

What it doesn't change

This controls the MFA requirement on each account. The actual MFA prompt and enrolment happen at sign-in — a member who hasn't set up MFA yet is walked through it when they next sign in, rather than being locked out. This matters most for students: a child who was locked out couldn't recover their own access the way a member of staff usually can, so neither setting ever works that way.

If your school uses a trusted IP allowlist, sign-ins from those addresses continue to behave as configured — the same allowlist applies to both settings.

Both settings are per-school and admin-only, and every change is logged in the audit trail.

Related

Was this helpful?