On this page
What 2FA does#
2FA adds an extra verification step to access an account or network. It’s often called multi-factor authentication (MFA).
2FA typically requires 2 of the following:
- Something you know – your username and password or PIN.
- Something you have – a security key or an authenticator app on your phone.
- Something you are – your fingerprint, face, or voice.
Why 2FA is important#
Microsoft reports that 2FA authentication blocks more than 99.9% of common identity-based attacks against accounts. 2FA is one of the most effective ways to protect school systems and data.
Schools and kura must meet the requirements of Principle 5 of the Privacy Act by keeping student and staff personal information secure.
You should still use a strong password and have good security practices when using your devices.
Where 2FA should be enabled#
If you are responsible for managing your school’s network, you can centrally manage all staff 2FA requirements, including any exemptions or conditions from the admin portal.
We recommend that 2FA or multi-factor authentication (MFA) is mandatory for:
- all administrator and financial accounts
- all staff accounts that access Student Management Systems (SMS)
- all staff accounts that access Microsoft 365 or Google Workspace
- any account that has access to personal information, financial information, or critical school systems.
Schools should consider requiring MFA for all staff as a standard security control.
This should be set out in your school's cyber security policy.
Authentication methods#
Authenticator apps#
This is the most common 2FA method at schools. Using an app on your smartphone, you receive a 1-time code which you must enter within a set timeframe.
Passwordless authentication#
Passwordless authentication allows users to sign in without entering a password. Instead, users verify their identity using something they have or something they are, such as:
- facial recognition or fingerprint recognition
- a passkey stored on a device
- a security key (such as a YubiKey)
- approving a sign-in request through an authenticator app.
Password authentication can provide a better user experience while reducing the risk of password theft and phishing attacks.
Where supported, schools should use phishing-resistant authentication methods such as passkeys, security keys, or biometric sign-in instead of SMS verification codes.
Security keys#
A security key, such as a YubiKey, is one of the most secure ways to implement 2FA and can be an option for staff who do not have a smartphone.
We have a small number of YubiKeys available for schools that would like to try them. To request them, contact us.
Email: [email protected]
Implementing 2FA#
Google#
Google has guidance for administrators on setting up 2FA for Google Workspace.
Deploy 2-Step Verification – Google Help
For technical staff, you can add further security control based on security posture, IP range, or geographic location with Context-Aware Access.
Protect your business with Context-Aware Access – Google
Microsoft#
Microsoft recommends requiring 2FA or MFA via Security Defaults or Conditional Access Policies.