Skip to main content

MFA methods

The MFA Methods page lists every sign-in method AuthCop offers. A method must be turned on here before any access policy can allow it.

Who can use this page: MFA Policy Manager or Global Administrator.

The MFA Methods page, with separate lists for Students, Caregivers and Teachers, each showing whether a method is enabled.

How the list is arranged​

Methods are grouped by who helps the student prove who they are:

ListMethods where…
Studentsthe student proves it themselves, for example with a QR code, authenticator app, passkey or email code.
Caregiversa parent or caregiver approves the sign-in. (Preview)
Teachersa teacher approves the sign-in.

A tick in Enabled means the method is turned on for your school.

Change a method​

  1. Select the method.
  2. Turn Enabled on or off.
  3. Change any other settings for that method (see below).
  4. Select Save.

How this affects sign-in: turning a method off removes it from the sign-in page for everyone, even if a policy allows it. Make sure students still have another method they can use, or they may be blocked. Turning a method on does nothing until an access policy allows it.

Portal permissions​

Methods that are set up for each student (such as QR codes and authenticator apps) have a Portal Permissions table. It controls whether users can View, Create or Delete their own methods in the User Portal, and whether caregivers can do the same for their students in the Caregiver Portal.

Preview

The User Portal and Caregiver Portal are still being built. These settings are saved now and will be used when the portals are released.

Method settings​

QR Code​

Students hold their own QR code card up to their device's camera. Each code is unique to one student. There are no extra settings. To give students codes, see Generate QR Codes.

TOTP​

Students type the 6-digit code from an authenticator app. You set this up for a student on their MFA Methods tab.

Passkey​

Students sign in with a passkey saved on their device.

Email One-Time Passcode​

AuthCop emails a one-time code to the student's alternate email address (a personal email address, not their school one).

SettingWhat it does
Allow Students to edit their email address in the Student PortalLets students change their own alternate email address. (Preview)
Allow Parents to edit their students email address in the Parent PortalLets caregivers change their student's alternate email address. (Preview)
Request email address on login if none setIf a student has no alternate email address, the sign-in page asks them to add one.
Require email address on login if none setOnly shown when the setting above is on. The student must add an address before they can carry on.

You can also set a student's address yourself on their Details tab.

Teacher​

A teacher approves the sign-in on the Teacher MFA Requests page.

SettingWhat it does
Automatically Create Teacher Request in Portal on student sign inCreates a teacher request as soon as the student reaches the sign-in page, so they don't have to ask for one. If a teacher approves it, the student is let straight in.
Require Number MatchingThe teacher must enter the ticket number shown on the student's screen. This makes sure the teacher approves the right student.
Multiple Choice Number MatchingInstead of typing the number, the teacher picks it from a list.
Number of options to showHow many numbers are in the list (3 to 12).
Number of number matching failed attemptsHow many wrong numbers the teacher can pick before the request fails. With multiple choice, this can be at most a third of the number of options.

Caregiver (Preview)​

A linked caregiver approves the sign-in.

SettingWhat it does
Require Number MatchingThe caregiver must match the number shown on the student's screen.
Number of number matching failed attemptsHow many wrong numbers are allowed before the request fails.
Send Email Confirmation to CaregiversEmails the caregiver when the student signs in. Without number matching, they can approve by selecting a link. With number matching, the email gives them the number instead.

Teams and Teacher Teams (Preview)​

Approval through Microsoft Teams. These methods are still being built.