Starting October 2026, staff logging into school accounts must verify identity via a one-time code sent to their individual email. Account admins must ensure each staff member has a unique profile with a personal email, review permissions, and remove former staff. This enhances data security by ensuring verified, identifiable access.
What's changing?
As a staff member logging into your school's online account, you will be required to verify your identity by entering a one-time code sent to the email address associated with your profile.
You may opt to be remembered for up to 30 days on your device. This option should not be used on shared or public devices.
This change follows another recent security update that prevents concurrent multiple sessions for staff users.
Related article: Security update – concurrent staff logins prevented
When?
This change will be introduced in October 2026.
What do you need to do?
Account administrators should review and update the list of staff members within your account.
- Ensure that every person who requires account access has their own user profile and login details, and that their individual (work) email address is listed on their profile.
- Do not use shared or generic email addresses.
- Review each staff member's permissions. If needed, you can limit user's access within the account by changing their role and assigned year levels and tags.
- Delete any existing staff users who have left your school or no longer require access to the account.
As a staff member, if you know that you currently share a login to your school's account with colleagues, please speak with your account administrator(s) about reviewing and creating individual staff logins.
Why is this happening?
ACER takes its data security obligations seriously. This change helps ensure that all staff users accessing protected school and student data are identifiable and verified.