Multi-factor authentication
MetCISA goal: Measurably increase the use of MFA across the manufacturer’s products.
Every administrator account supports time-based one-time password (TOTP) multi-factor authentication from any standard authenticator app, so districts are not locked into one vendor. Enrollment secrets and recovery codes are protected at rest and are never redisplayed after setup.
District administrators can require MFA across their entire organization, so enrollment is not left to individual discretion. This is the control CISA points to as the strongest version of this goal: enforcement at the organization level rather than a per-user suggestion.
We also support standards-based single sign-on in the baseline product at no additional cost, through Google Workspace, Microsoft 365 and Entra ID, ClassLink, and SAML 2.0 for identity providers including Okta, OneLogin, ADFS, Ping, and Shibboleth. Districts that already enforce phishing-resistant MFA at their identity provider inherit that posture in Manage1to1 without buying an upgraded tier.
