Multi-factor authentication (MFA)
Multi-Factor Authentication (MFA) adds an extra layer of security to Synap by requiring users to verify their identity using an authenticator app, such as Google Authenticator, when signing in.
Users can enable individual MFA themselves from their account page. On Pro or higher plans, or admins can enabled enforced MFA on different user types.
Individual MFA
Any user of any type on Synap can set up person MFA by navigating to their account page and following the set up MFA steps

Users need to have the Google Authenticator App installed on a device, and follow the steps on platform to generate the verification codes.

Once enabled users will be required to use the code generated through your authenticator app every time they need to login.
Enforced MFA
Portals can require Multi-Factor Authentication (MFA) for users across the portal from Settings > Authentication. For an admin to enable MFA on other user types, they must have MFA enabled on their own account, see the above instructions on individual MFA.
MFA can be enforced independently for:
Admins
Educators, Managers and Markers
Students
You can enable MFA for any combination of these user groups depending on your organisation's security requirements.
MFA enforcement is available on Pro plans and above. The admin enabaling enforced MFA must have it enabled on their individual account first.
Enabling MFA enforcement
Navigate to Settings.
Select Authentication.
Under MFA enforcement, enable MFA for the required user groups.
Confirm the prompt to apply the change.
Once enabled, users in the selected groups will be required to set up MFA before they can continue using Synap.
Existing users
Existing users who do not already have MFA configured are not logged out immediately. Instead, the next time they navigate around the platform or perform an action, they will be prompted to set up MFA using an authenticator app before they can continue. This makes it possible to roll out MFA without resetting passwords or recreating accounts.
Best practice: Avoid enabling MFA enforcement while students are actively taking exams, as users may be prompted to complete MFA setup during their session. We recommend enabling MFA outside of examination windows.
New users
Any new users created after MFA enforcement has been enabled for their user group will be required to configure MFA as part of completing their account setup.
They will not be able to finish setting up their account until MFA has been successfully configured.
Last updated
Was this helpful?