Security & 2FA

The Security page lets you manage your account’s security settings, including two-factor authentication (2FA) and social login connections.

How to Get There

Click your user menu (the circle icon in the top-right corner) and select Security to open this page.

Security settings with 2FA configuration The Security settings page showing two-factor authentication configuration

Two-Factor Authentication (2FA)

Two-factor authentication adds an extra layer of security to your account. When enabled, you’ll need both your password and a code from your authenticator app to log in.

Setting up 2FA

  1. Go to Settings → Security.
  2. Click Enable Two-Factor Authentication.
  3. Scan the QR code with your authenticator app (e.g., Google Authenticator, Microsoft Authenticator, Authy).
  4. Enter the 6-digit code shown in your authenticator app to confirm.
  5. 2FA is now active on your account.

Logging in with 2FA

  1. Enter your email and password as normal.
  2. You’ll be prompted for a verification code.
  3. Open your authenticator app and enter the current 6-digit code.
  4. You have 5 minutes to enter the code before it expires.
  5. After 5 failed attempts, you’ll need to start the login process again.

Disabling 2FA

  1. Go to Settings → Security.
  2. Click Disable Two-Factor Authentication.
  3. Confirm the action.

Disabling 2FA reduces the security of your account. We recommend keeping it enabled, especially for accounts with safeguarding or admin access.

Social Login

Ask.School supports signing in with your existing Google or Microsoft account. This is convenient if your school uses Google Workspace or Microsoft 365.

Supported providers

Provider Notes
Google Works with any Google account, including Google Workspace (school) accounts
Microsoft Works with Microsoft 365 and personal Microsoft accounts

How it works

  1. On the login page, click Sign in with Google or Sign in with Microsoft.
  2. You’ll be redirected to the provider’s login page.
  3. Sign in with your account and grant permission.
  4. You’ll be returned to Ask.School, logged in.

Important notes

  • Social login is only available if you have been invited to a school on Ask.School. You cannot create a new account through social login alone.
  • If your email address matches an existing invitation or account, the social login will be connected automatically.
  • You can connect multiple social accounts to the same Ask.School account.

Data security

Ask.School takes data security seriously:

  • Encryption — Sensitive personal information (names, emails, phone numbers) is encrypted at rest.
  • Row-Level Security — Each school’s data is isolated at the database level. Schools cannot see each other’s data.
  • Session management — Login sessions are secured and managed through encrypted cookies.
  • Rate limiting — Login attempts are rate-limited to prevent brute-force attacks.

Good to Know

  • We recommend all staff accounts enable 2FA, especially those with safeguarding or admin permissions.
  • Social login does not bypass 2FA — if you have 2FA enabled, you’ll still need your authenticator code.
  • If you lose access to your authenticator app, contact your school’s administrator for help.

Next Steps