Skip to content
English
  • There are no suggestions because the search field is empty.

Set up MFA for your admin account

Enable multi-factor authentication for your account in your user profile settings.

In this article

Requirements

Update phone number used for SMS MFA

Set up MFA with Authenticator App

Sign in using MFA

Troubleshooting

Protect your admin account with multi-factor authentication (MFA). MFA adds a critical layer of security by verifying your identity with a second factor, such as an SMS code or an authenticator app. This helps prevent unauthorized access if your password is compromised.

MFA is mandatory for all SchoolDay admin users. SMS authentication is enabled by default, and you can add an authenticator app for enhanced security. Use this guide to set up your MFA methods, sign in, and manage your account.

To activate MFA for non-admin users, see Enable Passport Login for your organization

Requirements

  • District Admin, Primary District Admin, and Vendor Admin permissions.
  • (District admins only) Installing Google Authenticator, Microsoft Authenticator, Authy, etc., on a smartphone to use the Authenticator App MFA.

Available MFA factors

SchoolDay supports multiple authentication factors to help secure user accounts. You can enable one or more factors, depending on the level of protection needed.

  • SMS Mobile phone: Requires a mobile phone or email. Users receive a one-time code and enter it with their password.
  • Authenticator App (TOTP): Optional secondary factor. Requires a compatible app. Users enter the temporary code generated by the app along with their password.

Update phone number used for SMS MFA

If you change your phone number, you need to update the number used for SMS authentication. This ensures you continue to receive one-time verification codes required for login. Since SMS is a required authentication factor, you cannot sign in if the registered number is no longer active.

  1. Go to the Connect > profile settings  > My Profile.
    image-png-Aug-10-2026-11-19-00-4123-AM
  2. In the SMS section, click Edit.
  3. Enter your phone number and click Continue.  You will receive a verification code on the provided phone number.
  4. Enter the verification code, and then click Verify.

Sign in using SMS MFA (default)

Note: SMS is the default MFA method and is required for all users.

  1. Go to https://sso.gg4l.com, select your organization, and enter your username and password, then click Sign In
  2. (If first-time sign in) When prompted for MFA, enter the phone number used for MFA.
  3. Enter the verification code, and then click Verify.
  4. (If first-time sign-in) Copy recovery codes and save them in a secure location.

Set up MFA with Authenticator App 

To configure an authenticator app from your account settings:

  1. Go to the Connect > profile settings  > My Profile.
  2. Turn on Authenticator App toggle.Security-Settings
  3. Scan the QR code displayed in your authentication app. Then, enter the code from the app for verification and click Verify.
  4. Copy recovery codes and save them in a secure location.

To set up an authenticator app during sign-in:

  1. Go to https://sso.gg4l.com, select your organization, enter your username and password, and then click Sign In
  2. When prompted to enter phone number, click Set up Authenticator App
  3. Scan the QR code displayed in your authentication app. Then, enter the code from the app for verification and click Verify.
  4. Copy recovery codes and save them in a secure location.

Sign in using MFA

You can sign in with SMS or an authenticator app, depending on the MFA method set up for your account. 

  • SMS (default): Go to sso.gg4l.com, select your organization, enter your username and password, click Sign In. If this is your first time signing in, enter the phone number used for MFA when prompted. Then enter the verification code sent to your phone.  
  • Authenticator app (district admins only): Go to sso.gg4l.com, sign in with your username and password, then enter the code from your authenticator app and click Confirm.

If this is your first time signing in, copy your recovery codes and save them in a secure location.

If you sign in with a recovery code, MFA is turned off immediately for your account. You must set up your MFA factors again the next time you sign in. 

Verify the configuration

  • Sign out and sign back in. You should be prompted for your second MFA factor before you reach the SchoolDay dashboard.

Troubleshooting

Symptom

Cause

Fix

Authenticator app codes are rejected

App and server clocks are out of sync

Confirm your phone's date/time is set to automatic, then retry

Lost the phone used for MFA

No access to SMS or authenticator app

See Recover access using MFA recovery codes

Next steps