Set up 2FA
2FA is mandatory for every Schoolysoft account.
Option 1 — TOTP app (recommended)
Compatible apps: Google Authenticator, Authy, Microsoft Authenticator, 1Password.
- Log in with your password.
- The 2FA setup page appears.
- In your TOTP app: tap + -> Scan a QR code.
- Scan the QR code shown.
- Enter the 6-digit code -> click Confirm.
Tolerance window
Schoolysoft accepts TOTP codes within a tolerance of +/- 60 seconds around the current time. This covers small clock drifts without weakening security. If your code is consistently rejected beyond this window, resync your phone’s clock.
Recovery codes
After setup, 8 single-use codes are provided. Store them in a password manager.
Option 2 — FIDO2/WebAuthn key (mandatory for Super Admin)
Compatible keys: YubiKey 5, Google Titan, TouchID/FaceID.
- Choose Use a security key.
- Insert the YubiKey or activate TouchID.
- Touch the key’s button when it blinks.
Common problems
| Symptom | Likely cause | Solution |
|---|---|---|
| Code rejected (“The code you entered was not recognised”) | Clock drift, or expired code | Check your authenticator app and try again with the code currently shown |
| Code rejected every time | Clock drift > 60 s | Sync the phone’s clock |
| App deleted | Phone lost | Use a backup code |
| Key not recognised | Browser without WebAuthn | Use Chrome, Firefox, Safari or Edge |
Error messages are intentionally generic (e.g. “The code you entered was not recognised”), without detail on the exact cause, for security reasons.
- Phone lost: use a recovery code to log in. Regenerating recovery codes is available in My account -> Security, but reconfiguring MFA (changing method or device) is not self-service.
- No backup codes left / authenticator lost with no code available: contact Schoolysoft support — only support can reset a user’s MFA. Your school’s administrator cannot perform this reset.