Live webinar: How the fastest growing firms scale without the admin

See how top practices manage staff, tasks and deadlines in one place. Live demo, real questions answered. Save your seat before it starts.
00 days
00 hrs
00 min
00 sec
Save My Seat
  • Resources
  • MFA Is Coming to HMRC Agent Accounts: What to Fix Before September 28th

MFA Is Coming to HMRC Agent Accounts: What to Fix Before September 28th

HMRC switches on multi-factor authentication for all remaining agent accounts between September 28th and October 15th 2026.

Sep 11, 2026 |Elizabeth Sullivan |5 Minute Read
Woman in Scandi Office Casual Wear

The Deadline Almost Nobody Has Diarised

Ask a UK practice owner what is on their compliance calendar this autumn and you will hear about quarterly updates, the January rush and Companies House reform. Very few will mention September 28th 2026. They should.

Between September 28th and October 15th 2026, HMRC will switch on multi-factor authentication (MFA) for every remaining agent account that does not already have it. That covers both the Agent Services Account (ASA) and the older HMRC online services for agents account (OSA) that most firms still use for Self Assessment and Corporation Tax. The voluntary opt in phases closed on 31 July, with just over 20,000 accounts switched on early. Everyone else is now in the mandatory tranche.

The catch is that HMRC will not tell you your exact date. Activation happens between 8am and 9am, Monday to Thursday, across that three week window. If you log in one morning and get an access code challenge, that is your day. If you are not ready, that is also the morning you lose access to your client records.

 

Why HMRC Is Finally Doing This

Agent accounts have been a soft target for years. Fraudsters have used hijacked agent credentials to file fabricated VAT returns and Self Assessment CIS repayment claims, redirecting refunds to bank accounts they control. Firms have described weeks of undetected remote access, clients to apologise to, ICO notifications to make and reputations to rebuild. Small practices have been hit just as hard as large ones, in some cases because the approach was tailored to them using the name of a genuine local business.

MFA has protected personal tax accounts and business tax accounts for years. Agent accounts, which hold the keys to hundreds or thousands of taxpayer records, did not. This change closes that gap. It is not a nuisance dressed up as security. It is the single most effective control available, and it blocks the overwhelming majority of credential based attacks.

 

What Actually Changes at Sign In

The journey becomes the same one your clients already use. You enter your user ID and password, then you enter a six digit access code. Nothing more exotic than that.

Two important points of reassurance:

  • MFA applies to direct logins to the ASA and OSA through a browser.
  • It should not disturb the software authorisation you already use to file MTD submissions, where authorisation codes refresh roughly every 18 months.

Also note that activation is applied at Government Gateway Identifier level. When the main account is switched on, every linked staff and admin account underneath it is switched on at the same moment.

 

The Decision Every Firm Has to Make

Before the switch on, you need to decide how your team will access HMRC. There are two workable models.

Option one, individual logins for every member of staff. This is HMRC's preferred approach and it is the more secure one. Each person sets their own password and their own access code method, and administrators can remove a leaver's access cleanly. The friction is client allocation. On the legacy OSA, clients do not appear automatically for a new standard user. An administrator has to allocate them, and there is currently no bulk allocation tool. If you have 4,000 clients and 20 staff who all need full access, do the maths before you commit. On the ASA the picture is better, because Access Groups let you manage which staff see which clients. Access Groups is still in private beta, so if the invitation banner is not showing in your ASA you will need to ask HMRC to enable it, and allow about a week.

Option two, keep shared credentials and use time based codes. HMRC does not prefer this, but it is explicitly supported. Multiple staff can use the same credentials at the same time provided each of them has an authenticator app set up from the same secret key. It avoids the allocation problem entirely. The trade off is governance. When someone leaves, you must change the password and refresh the MFA method, or they can still get in.

 

How Your Team Will Receive Codes

  • Authenticator app. HMRC's recommendation for most organisations. Codes are generated on a phone, tablet or computer with no need for signal or internet, and are live for 30 to 60 seconds. This is the only realistic option for shared credentials. Enterprise password managers and browser extensions can also generate these codes with better logging and central control.
  • Text message. A six digit code, valid for up to 15 minutes, sent from 60551 in the UK. Less reliable for non UK registered phones.
  • Voice call. An automated call from 01749 608007 reading out a code valid for up to 15 minutes. Useful where texts are unsuitable, but no good for a switchboard.

HMRC recommends setting up at least two methods so there is always a fallback. Without one, a lost phone means a call to the online services helpdesk.

 

The Mistake That Will Lock You Out on Day One

Here is the trap. Some firms already have MFA settings sitting on their accounts from years ago, perhaps set up by someone during MTD for VAT. If those settings point at a mobile number belonging to a former employee, or a device nobody still has, you will be challenged for a code you cannot receive. That is a lockout on the first morning, not an inconvenience later.

The second trap concerns shared logins. If you do nothing before your activation date, the first person to log in that morning is the one HMRC asks to choose the access code method. That could be a junior member of staff tying your firm wide credentials to their personal mobile. Set it up deliberately, in advance, or give your team crystal clear instructions about what to do if they are prompted.

 

Your Three Week Checklist

  • Check your access code settings on every account today. Look under your details, password settings, then how you get your access codes. Update anything out of date.
  • Make sure you have at least two administrators per account. An administrator can reset MFA for other people but not for themselves, so a single admin is a single point of failure.
  • Decide shared or individual logins, per account, and write it down.
  • Choose an authenticator app and a backup code method, then set them up now rather than on the day.
  • Store the secret key or seed key securely and separately from the user ID and password. With it, you can rebuild the app on a new device. Without it, you are calling the helpdesk.
  • Name each credential clearly in the authenticator app, for example VAT, Income Tax London office, so entries do not overwrite each other.
  • Delete Government Gateway credentials from any legacy or lapsed tax software you no longer use.
  • Brief the whole team before 28 September, including who to contact internally when a code fails.
  • Write the ongoing rules now: credentials deleted when staff leave, shared passwords and QR codes refreshed on departure, settings reviewed quarterly.

 

Make It a Client Conversation as Well

There is a commercial angle here that is easy to miss. Your owner managed clients are being targeted by the same phishing campaigns, and many of them have never enforced MFA on their own email, cloud accounting or banking. A short note explaining what your practice has just done, and why they should do the same, positions you as the adviser who takes their data seriously. Firms that treat security as a service rather than an IT chore find it is one of the easier advisory conversations to start.

 

The Bottom Line

This is a small piece of admin with a disproportionate downside if you ignore it. Twenty minutes spent in your ASA and OSA this week is the difference between a smooth transition and a morning spent on hold to the online services helpdesk while client work stalls. The window opens on the 28th of September. Treat that as your deadline, not the 15th of October, and get it done before the pre January workload closes in.