Overview
This article documents the application setting that defines the message shown to a user when the two-factor authentication step of the password reset (‘Forgot Password’) process cannot be completed successfully. This setting is part of the institute’s Security configuration and only affects the specific moment where two-factor verification during a password reset attempt fails or cannot go through.
What This Setting Does
This setting lets the institute define the exact text that Classter displays on screen when a user tries to reset their password using two-factor authentication, but the verification step does not succeed. The text is entered as free-form, formatted content, so headings, bold text, and links can be used if needed.
The setting comes with a ready-to-use default message already filled in, so the feature works correctly even before the institute writes a custom message.
Only one specific message is controlled by this setting: the one shown for an unsuccessful (failed) two-factor verification attempt. A separate setting controls the message shown when the verification succeeds (see Notes).
Where It Is Used
This setting is found at: Main Settings > General Settings > Security Settings > Basic Settings.
It is applied only during the password reset process, and only at the specific step where the user is asked to confirm their identity through two-factor authentication (typically a verification code). If that verification step cannot be completed – for example because the verification code cannot be delivered to the user – the text configured in this setting is displayed to the user on that screen, instead of a generic error.
This message is never shown anywhere else in the application. It has no effect on regular sign-in, on password changes made from inside the application by an already signed-in user, or on any other security screen.
Business Logic / Behavior
The following business rules apply to this setting:
- Two-factor authentication during password reset – and therefore this message – only applies to Parent (Guardian) accounts. Student, Teacher, and other staff accounts are not affected by this setting, since two-factor verification is not part of their password reset process.
- This message is only ever relevant when two-factor authentication for the password reset process has been switched on for the institute. If that master setting is off, two-factor verification never happens during password reset, and this message is never shown.
- If this field is left empty, Classter automatically falls back to the standard default message, so users are never shown a blank or missing message.
- In practice, an unsuccessful two-factor verification typically happens when the required verification step cannot be completed – for example, when the account has no mobile phone number on file to receive a verification code. In this situation, Classter generally still finalizes the requested password change, but keeps the account inactive until an institute administrator follows up with the user, which is why the default wording of this message explains that the password was changed but the account is temporarily disabled.
- Whenever this scenario occurs, the institute employee configured to receive these notifications (see Notes) is informed automatically, so that the promise made in the message – that an administrator will activate the account – is actually followed through on.
Example(s)
Example scenario: Alpha Institute has enabled two-factor authentication for the password reset process for parents and guardians. Maria P., a parent at Alpha Institute, forgets her password and requests a reset. She follows the link in the reset email, but the mobile number on her account is outdated, so Classter cannot deliver the verification code needed to confirm her identity. Because this step cannot be completed, Classter shows Maria the text configured in this setting, and also notifies the administrator that Alpha Institute has designated to follow up on unsuccessful attempts – for example, George S. from the registrar’s office.
For reference, the standard description and example provided for this setting reads as follows:
Main Settings / General Settings / Security Settings / Basic Settings / Unsuccessful message for 2-factor authentication
Here you can enter free text, which will be displayed on the user’s screen when the user cannot successfully complete the password reset using two-factor authentication.
Example
Setting -> Active -> The password has been changed. Your account, though, is disabled. An administrator of the institute has been notified and will activate your account after getting in contact with you.

When to Use
When to Enable
Customize this message whenever the institute wants password-reset communication to match its own tone, include specific contact details such as a support email or phone number, or add extra instructions for parents and guardians who are not able to complete two-factor verification. This is most relevant for institutes that have already turned on two-factor authentication for the password reset process and want full control over what users see if that step is unsuccessful.
When to Disable
There is no separate on/off switch for this specific message, since it is a message text rather than a toggle. It has no effect, and does not need to be reviewed or customized, when two-factor authentication for the password reset process is turned off for the institute, since in that case the verification step this message relates to never takes place.
Notes
Related settings:
- ‘Use 2-factor authentication for relatives at forgot password process’ (‘Main Settings > General Settings > Security Settings > Basic Settings – Use_Two_Factor_Authentication_At_Forgot_Password’) – the master switch that determines whether two-factor authentication is used at all during the password reset process. It must be enabled for the unsuccessful message to ever be shown.
- ‘Successful message for 2-factor authentication’ (‘Main Settings > General Settings > Security Settings > Basic Settings – Two_Factor_Authentication_Message_At_Forgot_Password_On_Successful’) – the counterpart message shown when the two-factor verification during password reset succeeds.
- ‘Employee receiving notification for unsuccessful forgot password request’ (‘Main Settings > General Settings > Security Settings > Basic Settings – Two_Factor_Authentication_At_Forgot_Password_Employee_Receiving’) – defines which employee is notified when a two-factor verification attempt is unsuccessful, so they can follow up with the user as the message describes.
This setting behaves the same way whether the institute operates in Higher Education Mode or in the standard (K-12) mode. There is no difference in how or when this message is shown between the two modes.
The message supports basic text formatting, such as bold text or links, so institutes can make key information – like a contact email or phone number – stand out clearly.