Overview
This article explains the purpose and behavior of the “Enable 2-Factor Authentication for the following actions” setting. This setting lets an institution choose which sensitive actions require a user to confirm a one-time pass code before the action is completed. It works together with a separate setting that controls how the pass code is delivered (see Notes).
The setting “Enable Two-Factor Authentication for the following actions” includes the option: Consents & Admission Data. This ensures that changes to consents or admission data require additional authentication for security.
What This Setting Does
This setting is a multi-select list. An administrator can choose, independently, any combination of the following actions to protect with an extra verification step:
- Consents & Admission Data – confirming a Consent (also called Permission or Approval) or submitting/updating admission-related information.
- Profile Changes – saving changes to personal profile information.
- Quick Admission – submitting a Quick Admission application.
- Signatures – electronically signing a document.
For any action selected here, the user performing that action is asked to enter a one-time pass code before the action is accepted and saved. For any action left unselected, the action completes normally, with no extra verification step.
Key Features:
- When enabled for Consents & Admission data, users will need to authenticate changes using a two-factor authentication process.
- Users receive a PIN code via email or SMS to complete the process.
Where It Is Used
This setting is found on the Basic Settings tab of Security Settings, under Main Settings > General Settings > Security Settings > Basic Settings.
Depending on which actions are selected, the extra verification step appears at different points across the application:
- Consents & Admission Data – when a parent, guardian, or student confirms a consent form or admission-related information.
- Profile Changes – when a user updates and saves their own personal profile details.
- Quick Admission – when an applicant submits a Quick Admission request.
- Signatures – when a user is asked to electronically sign a document.
The pass code delivery channel (email or SMS) is controlled by a separate related setting, described in Notes. This setting only decides which actions trigger the request for a pass code, not how the pass code is sent.
Go to Main Settings > General Settings > Security Settings > Basic Settings > Enable 2-Factor Authentication for the following actions.

Business Logic / Behavior
Each of the four actions can be enabled or disabled independently of the others, so an institution can require the extra verification step only for the actions it considers sensitive, while leaving the rest unaffected.
When a user performs an action that has been selected here, the system generates a one-time pass code and delivers it through the channel configured in the related Message Type setting (email or SMS). The user must enter the correct pass code before the action is confirmed and saved.
This setting has no effect unless a delivery channel (email or SMS) is also configured in the related Message Type setting. If actions are selected here but no delivery channel is configured, the pass code cannot be sent, and the corresponding action completes without requiring extra verification. For this reason, the delivery channel should always be configured together with this setting.
This behavior is identical whether the institution is operating in K-12 mode or in Higher Education mode. All four actions are available and behave the same way in both modes.
How It Works:
1. Setting Activation:
- Navigate to the settings page.
- Enable the option “Active for Consents & Admission Data” under the Enable Two-Factor Authentication setting.
2. Authentication Process:
- When users attempt to consent to a change, they are prompted with a two-factor authentication process.
- A PIN code is sent to the user’s registered email.
- Users must enter the PIN code to complete the action.
Setting -> Active for Consents

Example(s)
Example 1:
Riverside Academy has enabled the extra verification step for Consents & Admission Data and Signatures, and has configured the related Message Type setting to Email. A parent, Maria P., logs in to confirm a consent form for her child. Before the consent is saved, the system sends a one-time pass code to Maria’s registered email address. Maria enters the code, and the consent is recorded as confirmed.
Example 2:
At the same institution, a staff member, George S., sends an enrollment contract to a teacher, Elena K., for electronic signature. Because Signatures is enabled, when Elena opens the document to sign it, the system sends her a one-time pass code by email. Elena enters the code, and only then is her signature accepted and the document finalized.
Example 3:
Because Profile Changes and Quick Admission are left unselected at Riverside Academy, a student updating their contact details, or an applicant submitting a Quick Admission request, can complete those actions directly, without being asked for a pass code.
Example Email:
- Users will receive an email with the subject line “Your Two-Factor Authentication PIN.”
- The email contains the PIN code required to proceed.

When to Use
When to Enable
Select one or more actions here when:
- The institution wants an extra layer of verification before certain sensitive actions – such as consents, admission data, profile changes, quick admission requests, or electronic signatures – are finalized.
- There is a risk that someone other than the account holder could otherwise complete one of these actions unnoticed, such as confirming a consent or signing a document on someone else’s behalf.
- The related Message Type setting is already configured with a delivery channel, so pass codes can actually be sent.
When to Disable
Leave an action unselected (or leave the whole list empty) when:
- The institution does not require extra verification for that particular action, and prefers a faster, uninterrupted experience for its users.
- Users affected by that action do not reliably have an email address or mobile phone number on file, which could otherwise prevent them from completing the action at all.
- The process is still being finalized and end users should not encounter unexpected verification prompts.
Notes
Related settings:
- “Message Type for 2-Factor Authentication” (Main Settings > General Settings > Security Settings > Basic Settings – TwoFactorAuthenticationType) – determines whether the pass code is delivered by email or SMS. This setting has no effect unless a channel is selected there.
- “Use 2-factor authentication for relatives at forgot password process” (Main Settings > General Settings > Security Settings > Basic Settings – Use_Two_Factor_Authentication_At_Forgot_Password) – a separate feature that applies only to the Forgot Password process. It does not use this setting and works differently, notifying a designated staff member instead of sending a pass code to the requester.
- “Enable Configuration for Higher Education” (Main Settings > General Settings > Higher Education Customization > Basic Settings – Xrisi_parametropoihshs_kolegiou) – switches Classter into Higher Education mode. It does not change the behavior of this setting.
Prerequisites:
- Ensure the type of message receipt is selected in: Main Settings > General Settings > Security Settings > Basic Settings > Message Type for Two-Factor Authentication.
