MFA for System Administrators
Managing multi-factor authentication as a system administrator
Overview
Multi-factor authentication (MFA) provides an additional layer of security when users sign in. As a system administrator, you can:
Help new users enrol in MFA
Reset MFA when a user cannot access their registered method
Generate a temporary code for users who cannot begin enrolment
Check and filter users by their MFA status
Important: Resetting MFA affects account security. Always verify the user’s identity using your organisation’s approved process before resetting MFA or providing a temporary code.
Positions
The following positions can MFA features with default security policies:
System Admin - User Management
System Admin & Data Entry
How new users set up MFA
When you create a contact and enable a user account, a welcome email is sent to the user.
The user will:
Open the link in the welcome email.
Create a password.
Request and enter the verification code.
Sign in with their new password.
Follow the prompts to secure their account with MFA.
The user can register:
An authenticator app
A mobile number to receive SMS verification codes
We recommend registering both methods where possible. This gives the user a backup if one method becomes unavailable.
A Skip for now option may appear during initial sign-in which allows for an initial 24 hour grace period before. The user must enable MFA after this time.
Reset MFA for a user
System Administrators can Reset MFA when a user has lost, replaced or can no longer access the device registered for MFA.
To reset MFA:
Verify the user’s identity using your organisation’s approved process.
Sign in as a system administrator for the user’s primary site.
Open the user’s record.
Select Reset MFA.
Review the warning and confirm the reset only when you are satisfied that the request is genuine.
Provide the generated temporary reset code to the verified user.
The temporary code expires after the period displayed on screen. Ask the user to use it within that time.
Note: Resetting MFA does not change the user’s password.
The user must then:
Sign in with their existing username and password.
Enter the temporary reset code when prompted.
Register a new MFA method.
Complete the verification steps and save the new method.
Help a user who has not enrolled in MFA
A user may be unable to sign in if:
They had not enrolled in MFA before it became mandatory; and
Their contact record did not contain a mobile number.
The user will be instructed to contact the system administrator at their primary site for a code.
To help the user follow the process to Reset MFA.
Check a user’s MFA status
You can view MFA information from the Contact datagrid.
Open the Contacts register.
Open the column selector.
Add the MFA status and Primary site columns.
These columns show whether each user has completed MFA enrolment and identifies the user’s primary site.
These fields are also searchable from the 'Additional filters' selector accessible from the search screen.
Find users with CQL
You can also use CQL to search for users according to their MFA status.
Users with MFA enabled (replace 'YourSiteName' with your domain name)
Users who have not completed MFA enrolment (replace 'YourSiteName' with your domain name)
Security guidance
When supporting an MFA reset:
Always verify the user’s identity first.
Only administrators for the user’s primary site can complete the reset.
Share temporary codes using an approved secure method.
Never send a temporary code to an unverified recipient.
Ask the user to use the code before the displayed expiry time.
Remind the user that an MFA reset does not change their password.
Encourage the user to register both SMS and an authenticator app.
Last updated
Was this helpful?
