Single sign on (SSO) – two factor authentication (2FA/MFA)

To help keep accounts secure, all users of the NHS Leadership Academy Single Sign-On (SSO) system are required to set up two-factor authentication (2FA), also known as multi-factor authentication (MFA).

Why do we need multi-factor authentication?

In recent years it has become clear that securing access with a single factor of authentication (i.e. passwords) is no longer enough to keep data safe. Security teams within the NHS, UK Government and the technology/healthcare industries are beginning to mandate two factor authentication as a method of securing access to services.

You may already be using multi factor authentication for services such as your bank, self assessment taxes, or email. Multi-factor authentication adds an extra layer of security to your account. As well as your password, you’ll need to provide a second form of verification, such as a code sent to your phone or generated by an authenticator app.

Before you start

Before setting up MFA, make sure you have access to either:

  • A mobile phone capable of receiving SMS messages, or
  • An authenticator application such as Microsoft Authenticator, Google Authenticator, Authy, or Apple’s Passwords app.

What does this look like?

The first time you sign in to one of our SSO-enabled services after MFA has been enabled, you’ll be asked to set up an authentication method. We recommend using an authenticator app where possible, as this is generally more secure and does not rely on mobile phone signal or text message delivery.

If you decide to receive text messages, you will be asked for your mobile phone number which will be used to send a passcode for future logins.

You may prefer to use an application such as Google Authenticator, Microsoft Authenticator, Authy or the iPhone Password app. You may select this as an alternative option during enrolment, at which point you will be provided a QR code to scan with your chosen app.

How will I get my login codes?

After setup, you’ll need a six-digit code each time you sign in.

Depending on the method you chose:

  • SMS authentication will send a code to your mobile phone.
  • Authenticator apps such as Microsoft Authenticator, Google Authenticator, Authy, or Apple’s Passwords app will generate a code for you.

Some password managers, including Bitwarden and 1Password, can also generate authentication codes.

Some applications will automatically attempt to register and fill in OTP (one time passwords or passcodes) to help you; it’s important to be aware which application you are using.

If you’re using an iPhone, scanning the QR code may store the authenticator in Apple’s Passwords app. If you’re unsure where your code is being generated, check the Passwords app first.

You will then need to confirm enrolment by providing the current 6 digit code. Once accepted, the process will direct you back to the website you were originally trying to access.

You should never share the generated number with anyone.

Never share authentication codes with anyone, including colleagues, managers, or anyone claiming to be from the NHS Leadership Academy. Our support team will never ask you for your authentication code.

What if I lose my phone or authenticator app?

Our support team are able to assist in these instances. Once your identification has been verified we are able to reset your two factor authentication enrolment. Once this is done, you will need to enrol once again using a new device or app.

How does this impact shared or generic accounts?

For security and auditing reasons, NHS Leadership Academy services are designed to be accessed using individual user accounts. Shared accounts and shared MFA codes are strongly discouraged, as they make it difficult to manage access, protect personal data, and investigate security incidents.

Given the current security landscape we would prefer people to use their own accounts and work with us to improve our services if an existing process requires shared access. Personal accounts allow us to more easily onboard and offboard users, control access to personal data, and audit authentication and authorization to our systems. By sharing your account details you are taking full responsibility for the actions anyone takes whilst logged in as you, and increasing the risk of a security incident.

How can I change my authentication method?

You can change your authentication method from within the Profile / Authenticators section of the Profile system. By deactivating the existing method, you can then choose a new method when you next login.

The mobile number shown in your Profile is separate from the phone number used for MFA. Updating one will not automatically update the other. You can manage the mobile number used for login codes from the Authenticators section of the profile system.

Why are authentication codes no longer sent by email?

Historically, some users were able to receive authentication codes by email. This method is no longer offered because it is no longer considered a sufficiently secure form of multi-factor authentication.

The purpose of MFA is to provide a second layer of security in addition to your password. If someone gains access to your email account, they may also be able to reset passwords and receive authentication codes sent to that same mailbox. In this situation, email can no longer provide an effective independent second factor of authentication. Security guidance increasingly recommends that authentication codes are delivered through a separate device or application, such as an authenticator app or mobile phone. These methods provide stronger protection against unauthorised access and help reduce the risk of account compromise.

Further Information

If you have any questions or concerns, please contact us via normal support channels.

For further information on the Profile system, please visit our Profile System support page.