More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
docs
betterdocs_faq

Message type for 2-Factor Authentication

Updated on July 9, 2026

5 min to read

 

Overview

This article explains the purpose and behavior of the Message Type for 2-Factor Authentication setting. This setting controls how a one-time verification code (pass code) is delivered to a user when the system requires an extra confirmation step before completing certain sensitive actions. It works the same way for both K-12 and Higher Education institutions.

 

What This Setting Does

This setting specifies the communication channel used to deliver a one-time pass code whenever the system asks a user to confirm a sensitive action with an extra verification step. Two channels are available:

  • Email – the pass code is sent to the email address on file for the user.
  • SMS – the pass code is sent as a text message to the mobile phone number on file for the user.

If no channel is selected, this extra verification step is effectively switched off: users are not asked for a pass code before completing the actions that would normally require one. Selecting Email or SMS is what activates the mechanism; which specific actions actually trigger a pass code request is controlled by a separate related setting (see Notes).

Main Settings / General Settings / Security Settings / Basic Settings / Message type for 2-Factor Authentication

If you specify a two-factor authentication, a message with one-time pass code is sent to the end user.

Here you can specify if this pass code is sent by email or by SMS.

1. Email

2. SMS

If you select Email, you will receive one-time pass code in your email.

If you select sms, you will receive one-time pass code in your mobile phone.

Note: You should select Email or SMS if you enable two-factor authentication in Main Settings / General Settings / Security Settings / Basic Settings.

 

Where It Is Used

This setting is found on the Basic Settings tab of Security Settings, under Main Settings > General Settings > Security Settings > Basic Settings.

It does not affect the regular sign-in process. Instead, it applies at the moment a user performs one of a small number of sensitive actions that the institution has chosen to protect with a pass code, such as:

  • Submitting or updating Consents
  • Changing personal Profile details
  • Completing a Quick Admission application
  • Signing a document electronically (Signatures)

Which of these actions actually require a pass code is controlled by a separate related setting described in Notes below. The Message Type for 2-Factor Authentication setting only decides how the pass code is delivered once one of those actions is triggered.

This setting is separate from the 2-factor authentication option available for relatives during the Forgot Password process. That option works differently and does not use this setting (see Notes).

 

Business Logic / Behavior

When a user performs an action that has been configured to require this extra verification, and this setting is set to Email or SMS, the system generates a one-time pass code and sends it through the selected channel:

  • If Email is selected, the pass code is sent to the email address recorded for that user.
  • If SMS is selected, the pass code is sent as a text message to the mobile phone number recorded for that user.

The user must enter the pass code correctly before the action is confirmed and saved. The pass code is valid only for a limited time; if it expires or is entered incorrectly, the user is asked to try again or request a new one.

Only one delivery channel is active at any time – the system does not automatically try the other channel if the first one fails. If the selected channel’s contact detail (email address or mobile phone number) is missing from the user’s profile, the pass code cannot be delivered and the action cannot be completed until the missing contact information is added. For this reason, an accurate email address or mobile phone number should be kept on file for anyone who may need to complete a protected action.

This behavior is identical whether the institution is operating in K-12 mode or in Higher Education mode. There is no difference in how this setting works between the two modes.

 

Example(s)

Example 1:

Meridian Academy has configured the extra verification step for Consents and Signatures, and has set the Message Type for 2-Factor Authentication to SMS. A parent, Maria P., logs in to review and confirm a consent form. Before the confirmation is saved, the system sends a one-time pass code by text message to Maria’s registered mobile phone. Maria enters the code and the consent is saved successfully.

Example 2:

At the same institution, a teacher, George S., attempts to electronically sign a document. Because George does not have a mobile phone number on file, the system is unable to send him a pass code and he is informed that the process cannot be completed until his contact details are updated. Once the school administrator adds George’s mobile phone number to his profile, he is able to complete the signature.

 

When to Use

When to Enable

Select Email or SMS when:

  • The institution wants an additional verification step before sensitive actions such as Consents, Profile Changes, Quick Admission, or Signatures are finalized.
  • Contact information (email addresses and/or mobile phone numbers) is reliably kept up to date for the users who will be affected, so pass codes can actually reach them.
  • The institution has already decided which specific actions should require this extra verification, using the related setting described in Notes.

When to Disable

Leave this setting with no option selected when:

  • The institution does not require an extra verification step for these actions, for example because other controls are already considered sufficient.
  • Contact information for affected users is not consistently available, which would otherwise leave some users unable to complete protected actions.
  • The institution’s process definitions are still being finalized and end users should not encounter unexpected verification prompts.

 

Notes

Related settings:

  • “Enable 2-Factor Authentication for the following actions” (Main Settings > General Settings > Security Settings > Basic Settings – TwoFactorAuthenticationActions) – defines which specific actions (Consents, Profile Changes, Quick Admission, Signatures) actually require a pass code. The Message Type for 2-Factor Authentication setting has no effect unless at least one action is selected here.
  • “Use 2-factor authentication for relatives at forgot password process” (Main Settings > General Settings > Security Settings > Basic Settings – Use_Two_Factor_Authentication_At_Forgot_Password) – a separate feature that applies only to the Forgot Password process for parents and relatives. It does not use this setting and works differently: instead of sending a pass code to the requester, it notifies a designated staff member.

Prerequisites:

  • Decide which actions should require this extra verification step using the related “Enable 2-Factor Authentication for the following actions” setting.
  • Make sure the users affected by those actions have a valid email address (if Email is chosen) or a valid mobile phone number (if SMS is chosen) recorded in their profile, otherwise they will not be able to complete the protected action.

If no option is selected for this setting, users will not be able to complete updates that involve sensitive information through the protected actions described above, since no pass code can be issued to confirm them.

 

 

Was this article helpful?