More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
docs
betterdocs_faq

Use 2-factor authentication for relatives at forgot password process

Updated on July 9, 2026

5 min to read

 

Overview

This article explains the application setting that adds an extra identity-verification step for parents and guardians who reset a forgotten password on the Parents Portal (Relatives Portal). The sections below cover what it does, where it applies, the business rules behind it, and when to turn it on or off.

For reference, the setting is documented in the system as follows:

Main Settings / General Settings / Security Settings / Basic Settings / Use 2-factor authentication for relatives at forgot password process

This setting only works for the parents’ portal.

When the user forgets the password, he clicks on the Forgot Password button and fills in his username and receives an email to reset the password and then receives one time pass code to the phone number he has registered in his profile.

Settings -> Active

 

 

Setting -> Inactive

If the setting is inactive, then the user receives only an email to reset their password

 

What This Setting Does

This setting decides whether a parent must confirm a one-time security code sent by text message (SMS), in addition to the usual password-reset email, when using the Forgot Password option on the Parents Portal.

When the setting is switched on, a parent who forgets their password receives both a password-reset email and a one-time security code by SMS to their registered mobile phone number. Both the emailed link and the SMS code must be used successfully before the new password takes effect. When the setting is switched off, the parent only needs the emailed reset link to set a new password, with no SMS step involved.

 

Where It Is Used

It takes effect on the Forgot Password screen of the Parents Portal (Relatives Portal) – the screen a parent reaches by selecting Forgot Password and entering their username when they cannot log in. The setting has no effect on the Student Portal or on Staff/Teacher accounts; those users always reset their password with the emailed link only, regardless of how this setting is configured.

 

Business Logic / Behavior

When the setting is enabled, a parent’s forgot-password journey works as follows:

  • The parent opens the Parents Portal, selects Forgot Password, and enters their username.
  • Classter emails a password-reset link to the parent’s registered email address, as it always does regardless of this setting.
  • Because the setting is enabled and the account belongs to a parent/relative, Classter also generates a one-time security code and sends it by SMS to the mobile phone number on file – normally the number saved on the parent’s own portal profile, or, if that is empty, the phone number saved on the parent’s contact/relative record.
  • The parent must supply this code correctly, together with completing the password reset, before the new password is applied. An incorrect code prevents the password from being changed.
  • The security code stays valid for a limited time after it is issued; requesting the process again produces a new code and cancels the previous one.
  • If no mobile phone number is available for the parent, the SMS code cannot be sent and the reset cannot be completed through this step. In this case, and generally whenever an attempt is unsuccessful, Classter automatically notifies the staff member chosen in the related “Employee receiving notification for unsuccessful forgot password request” setting, so the institute can assist the parent directly.
  • Once the code is confirmed successfully, Classter shows the parent a confirmation message, which can be customized through the related “Successful message for 2-factor authentication” setting.

When the setting is disabled, the SMS step above does not happen at all: the parent resets their password using only the emailed link, in the same way as Student and Staff/Teacher accounts.

Business rules that follow from this setting:

  • Only Parent/Relative accounts are ever affected by this setting; Student and Staff/Teacher accounts always use the email-only reset process, no matter how this setting is configured.
  • This setting works independently of the institute’s other two-factor authentication feature, the one covering actions such as consents, profile changes, quick admission requests, and signatures; turning this setting on or off does not change that separate feature, and vice versa.
  • A parent without a registered mobile phone number cannot complete the SMS step while the setting is enabled, even though the reset email is still sent to them as usual.

Prerequisites:

  • The institute’s SMS sending configuration must already be set up and working; without it, the one-time code cannot be delivered even if this setting is switched on.
  • Parents should have a mobile phone number recorded, either on their own portal profile or on their contact/relative record, so the one-time code has somewhere to be delivered.

 

Example(s)

Alpha Institute keeps this setting enabled for its Parents Portal. George S., a parent at Alpha Institute, forgets his password. He opens the Parents Portal, selects Forgot Password, and enters his username. He receives an email with a reset link and, moments later, a text message with a one-time security code on the mobile number saved in his profile. George follows the email link, enters the code from the text message, and sets a new password; Classter then shows him a confirmation message. If George’s mobile number had not been registered, the text message could not be delivered, and the institute’s designated staff contact would be notified automatically so someone could help him directly.

At Beta College, the same setting is switched off. When a parent, Maria P., forgets her password, she receives only the reset email. She clicks the link and sets a new password immediately, with no additional code to enter, because the setting is disabled.

This behavior is the same whichever mode the institute uses: it does not change between K-12 mode and Higher Education mode. What matters is only whether this setting itself is switched on or off for the institute, not which of the two modes the institute operates in.

 

When to Use

When to Enable

  • The institute wants an extra layer of identity verification before a parent can reset their password, for example, to reduce the risk of someone else resetting a parent’s password using only their username and email address.
  • Parents’ mobile phone numbers are reliably kept up to date in the system, so the SMS step will normally succeed.
  • The institute’s SMS sending configuration is already set up and working.

When to Disable

  • The institute prefers a simpler, faster reset process for parents, relying on the emailed link alone.
  • Parents’ mobile phone numbers are often missing or out of date, which could otherwise prevent parents from completing a reset.
  • SMS delivery is not available, not configured, or unreliable for the institute’s country or SMS provider.

Notes

Related settings, found in the same location, Security Settings > Basic Settings:

  • “Employee receiving notification for unsuccessful forgot password request” (Security Settings > Basic Settings – Two_Factor_Authentication_At_Forgot_Password_Employee_Receiving)
  • “Successful message for 2-factor authentication” (Security Settings > Basic Settings – Two_Factor_Authentication_Message_At_Forgot_Password_On_Successful)
  • “Unsuccessful message for 2-factor authentication” (Security Settings > Basic Settings – Two_Factor_Authentication_Message_At_Forgot_Password_On_Unsuccessful)

These three settings only refine what happens around this one (who gets notified, and what message parents see); they do not need to be configured for this setting to work, but they let the institute personalize the experience further.

A separate, unrelated two-factor authentication feature also exists in the same settings tab, covering actions such as consents, profile changes, quick admission requests, and signatures. That feature has its own settings and does not interact with the forgot-password process described in this article.

 

 

Was this article helpful?