Mandatory MFA - August 2026
This page explains the mandatory MFA update being rolled out in August 2026.
What is changing
From 21 August 2026, every user signing in to Crisisworks will be required to complete a multi-factor authentication (MFA) check at every sign-in. This applies to all users — those signing in with a username and password, and those signing in through single sign-on (SSO).
Today, MFA is optional and most users sign in with a password alone. After the change, a password alone will no longer be sufficient.
The change is part of Datalink's commitment to align Crisisworks with the Australian Cyber Security Centre's Essential Eight Maturity guidance on multi-factor authentication. It materially reduces the risk of account takeover from leaked or reused passwords — the most common attack faced by services like Crisisworks.
⬇️ Jump to MFA Set up Instructions
Key concepts
Multi-factor authentication (MFA) — a security check that uses two pieces of evidence to confirm you are who you say you are: something you know (your password) and something you have (your mobile phone). The check happens at sign-in.
SMS code — by default, MFA is performed by sending a one-time code to your mobile phone via SMS, which you enter at the sign-in screen to complete the check.
TOTP / authenticator app — an optional alternative MFA factor available through the existing MFA self-management screen in Crisisworks. You can add an authenticator app (such as Google Authenticator) as an additional second factor.
Primary site — every Crisisworks user has a primary site, which is the site that administratively manages them. The primary site is also the place where MFA recovery happens if the user loses their phone.
Recovery — the documented process by which a site administrator helps a user re-establish MFA after losing access to their device, including proof of identity.
What the user experience will look like
For most users the change is small and concentrated at one moment — the first sign-in after 21 August.
Username / password users
At your first sign-in after activation:
You enter your password as usual.
You receive a one-time code via SMS to the mobile number your site administrator has on file for you.
You enter that code on the sign-in screen and proceed normally.
The system remembers that your phone is now confirmed. Future sign-ins continue to involve an SMS code.
SSO users
At your first sign-in after activation:
You sign in through your organisation's identity provider as usual.
You will not be prompted for MFA by Crisisworks.
In the near future, SSO users who are also Crisisworks System Administrators will also need MFA for some functions
Administrators and power-users
While using some of the more sensitive functionality within Crisisworks, you may be asked to complete an additional SMS check based on a risk-based calculation by the system. This will cover functionality such as user management, bulk management and bulk exports.
Handling common scenarios
Once mandatory MFA is enabled, this section describes some common problems.
If your mobile number on file is wrong or out of date
You will not receive the SMS code.
Your primary site's administrator can update your number through the contact register, and you can try again immediately.
Adding an authenticator app for stronger protection
The existing MFA self-management screen lets you add a TOTP authenticator app alongside SMS. SMS remains the baseline for everyone; adding TOTP gives you a stronger second factor and an alternative if you do not have mobile reception when signing in.
Recovering if you lose your phone
Your primary site administrator can reset your MFA.They will confirm your identity using a documented proof-of-ID process before performing the reset. Datalink does not perform MFA recovery for end users directly — your site administrator is the support path.
Important: MFA setup instructions for users
🎬 How to Video - Multi-Factor Authentication
Users should check if their MFA is configured by viewing their Your User Account screen under the MFA section.
Once successfully configured they should see a green MFA Configured
icon under their Crisisworks ID.
If MFA is not configured, users should configure it using the Configure MFA button.
It is strongly recommended to set both mobile and One-Time Password options when configuring MFA.
Resetting your password
The email-based password recovery process remains the same for users that have set up MFA. For users that do not yet have an MFA, they will need to contact their administrator to add their mobile phone to their record before they can reset their password.
Crisisworks site administrators
The most important preparation happens on the customer side. By 18 August 2026, each site's administrators should:
Clean the contact register. Review every contact flagged as a user. Confirm the mobile phone number is current and correct. Remove the user flag from contacts who are no longer active. This is the single most important task — the mobile number on file is what makes MFA work at cutover.
Re-verify any stale numbers. Numbers that have not been updated within the last 18 months will be flagged in a cleanse list. The system will require these users to re-verify their number when they next sign in.
Onboard your administrators to MFA early. Each site administrator should enrol their own MFA before 21 August via the existing self-management screen. This ensures administrators are not themselves locked out at cutover and are available to support their end users.
Communicate to your users. Datalink will issue in-app and email communications, but a direct message from the site to its own users carries weight that vendor communications do not.
Last updated
Was this helpful?
