Skip to main content

Multi-factor authentication (MFA) for administrators: FAQs

What is MFA?

Multi-factor authentication (MFA) is a security method that requires two forms of verification to sign in: something you know (your password) and something you have (in this case, access to your email inbox, where a one-time verification code is sent). Even if a password is guessed, stolen, or compromised, an account protected by MFA cannot be accessed without the second verification step. MFA is a widely adopted standard for protecting accounts that hold sensitive data.

What is changing?

To strengthen account security, administrator sign-ins for Similarity and iThenticate 2.0 will include multi-factor authentication (MFA). In addition to your username and password, you will enter a one-time verification code sent to the email address associated with your admin account. MFA adds a second layer of protection to administrator accounts, significantly reducing the risk of unauthorized access.

Which email address will my verification code be sent to?

Your code will be sent to the email address associated with your Turnitin admin account, the same address where you receive other Turnitin account communications. If you are not sure which email address is on your account, you can check your profile after signing in. To confirm or update your email address, see our guides on editing your profile for Similarity and iThenticate.

Who does this apply to?

This change applies to administrators of Similarity and iThenticate 2.0 accounts who sign in directly with a Turnitin username and password. MFA does not apply to sign-ins through single sign-on (SSO) or access through an integration. No other user roles are affected at this time.

Do I need to do anything to prepare?

No setup or configuration is required. To ensure a smooth transition:

  • Confirm that the email address for each administrator on your account is active and accessible to them, since this is where verification codes will be sent. 
    • Account administrators can review and update user email addresses from the Users menu; see our guides on managing users for Similarity and iThenticate
  • Ask your IT team to whitelist Turnitin's email domains so verification emails are not blocked or delayed by your institution's firewall.

How does the new sign-in process work?

You will enter your standard Turnitin username and password as usual. You will then be prompted for a one-time verification code, which is sent automatically to the email address associated with your admin account. The code is valid for 15 minutes. Once you enter it, you will have full access to your account as normal.

What if I don't receive my verification code?

First, check your spam or junk folder, since verification emails are sometimes filtered. If the email is not there, confirm that the email address on your admin account is correct and accessible. You can request a new code from the sign-in screen if your code has expired. If codes are consistently delayed or missing, your institution's firewall may be filtering them; ask your IT team to whitelist Turnitin's email domains. If you are still unable to receive a code, contact Turnitin Support.

What if I no longer have access to the email address on my account, or can't remember which one I used?

If you can still sign in, check and update your email address in your profile as soon as possible. See our guides on editing your profile for Similarity and iThenticate. If you cannot sign in, another account administrator on your account can update your email address from the Users menu. If no other administrator is available, contact your Turnitin account representative, who can verify your identity and arrange for your admin details to be updated.

Can I opt out of MFA?

No. MFA applies to all administrator sign-ins as part of our improved security measures. Because administrator accounts hold your institution's most sensitive settings and user data, MFA provides a second layer of protection to administrator accounts, significantly reducing the risk of unauthorized access.

Will this affect instructors or students?

No. This current rollout applies only to administrator sign-ins. Instructors and students will continue to access and use their accounts exactly as they do today, and no other roles are affected at this time.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Powered by Zendesk