Multi-factor authentication (MFA) keeps your PASS account safe by checking it's really you when you log in.
The first half of this article explains how to set up MFA for the first time
The second half explains how to transfer MFA authentication to a new device
Once your administrator turns MFA on, PASS will guide you through a short, one-time setup the next time you log in. This guide shows you what to expect at each step.
You can choose how you'd like to verify:
By email - we send a one-time code to your registered email address
With an authenticator app on your phone, such as Microsoft Authenticator or Google Authenticator
⚠️ Please note: From 28 July 2026, MFA will be turned on automatically for all GP Connect users. If you use GP Connect, you'll be guided through this setup the next time you log in after that date — it only takes a couple of minutes.
Step 1: Log in to PASS
The next time you log in, you will see the Additional Security Verification screen. It shows the verification status of your email address and your authenticator app.
From this screen you can:
Click Verify now next to your email address to verify by email code
Click Configure now next to Authenticator to set up an authenticator app
💡 Tip: We recommend setting up both verification methods. If you're unable to receive a verification code by email, you can use the authenticator app instead. This is particularly useful if you're in an area with poor mobile signal.
Step 2: Choose how you'd like to verify
Both options work equally well, so pick whichever suits you.
Option A – Use an authenticator app
Click Configure now on the Authenticator row, then follow the steps on screen:
Install an authenticator app on your phone, such as Microsoft Authenticator or Google Authenticator.
In the app, select Set up account, then Scan a code.
Scan the QR code shown on your screen.
Click Next once you've scanned the code.
Enter the code your app generates when PASS asks for it.
💡 Tip: If you can't scan the QR code, click the "Can't scan QR code?" link to set it up manually instead.
Setting up Authenticator App for MFA
Choose an authenticator app – We recommend Microsoft Authenticator or Google Authenticator (both free, available on iOS and Android). Any standard TOTP-based authenticator app will work.
Download the app from the App Store (Google Authenticator App - App Store) or Google Play (Google Authenticator - Apps on Google Play).
Log in to PASS and go to your MFA/security settings.
Select "Authenticator App" as your MFA method and scan the QR code shown on screen using your chosen app.
Enter the 6-digit code generated by the app to confirm setup.
Every seven days, you'll be prompted to open your authenticator app and enter the current code
Tip: Codes refresh every 30 seconds, so make sure you enter the code before it expires.
Option B – Verify by email
If you'd rather use email, click Verify now next to your email address, then carry on to Step 3.
Step 3: Check your email for your code
PASS will send a one-time password (OTP) to your registered email address. The email will look like this:
⚠️ Important: Your code expires after 3 minutes, so have your inbox ready. Keep the code to yourself — no one from PASS or your office will ever ask you for it. If a code arrives that you didn't request, contact your office straight away.
Step 4: Enter Your Code
Go back to PASS, type your code into the "Enter code here" field, then click Verify.
💡 Tip: If your code hasn't arrived, click Resend and we'll send you a fresh one.
Step 5: You're all set
Once your code is accepted, you will see the Verification Successful screen, and your email address will show as Verified.
Click Proceed to PASS to carry on into the application.
💡 Tip: You can change your verification settings at any time from the Employee Details screen.
When will I be asked to verify again?
Once you're set up, you won't need to verify on every login. PASS will only ask you again in these situations:
Trigger | Detail |
Every 7 days | A regular check that keeps your account secure. |
Browser cache cleared | This removes your stored session, so PASS will ask you to verify on your next login. |
App uninstalled or cache cleared | This also removes your stored session, so you'll verify again on your next login. |
💡 Tip: If you find you're being asked to verify often, avoid clearing your browser or app cache unless you need to.
Having trouble?
If you haven't received the OTP code by email click re send. If it still doesn't come through this could be down to poor signal. If you have not set up the authenticator app as an alternative method please call support for assistance
Setting up the authenticator app and can't scan the code? Click the "Can't scan QR code?" link to set it up manually instead.
If you are trying to log in and you have no details to verify (as shown in the image below) this will be due to having no email address attached to your profile.
Please contact your office who can add this into your profile.
MFA - Transferring MFA to a new device
Multi-Factor Authentication (MFA) helps keep your PASS account secure by verifying your identity when you sign in. If you've changed your mobile device, you'll need to set up MFA again on your new phone.
Which situation applies to you?
Option 1: I still have my old device
If your old phone is still available, you can set up the authenticator app on your new device yourself:
Log in to PASS on your new device using your username and password.
When prompted for MFA, select Authenticator App.
On the setup screen, you'll see a QR code or a secret key.
Open your authenticator app (Microsoft Authenticator or Google Authenticator) on your new device.
Add a new account in the authenticator app and scan the QR code, or enter the secret key manually.
Enter the one-time code generated by the authenticator app to complete setup.
You're all set — your new device is now linked.
Option 2: I no longer have my old device
If you no longer have access to your old phone, you'll need us to reset your MFA so you can set it up again on your new device.
What to do:
Contact our Customer Support team as soon as possible.
Tel: 0330 094 0122
We will reset your MFA, which will allow you to configure it fresh on your new device.
Once reset, log in to PASS and follow the on-screen prompts to set up your authenticator app (as described in Option 1 above).
Please note: Until MFA is reset, you will not be able to log in. We aim to process resets as quickly as possible to minimise any disruption to care delivery.
Tips for a smooth setup
Download your authenticator app first — install Microsoft Authenticator or Google Authenticator on your new device before you begin.
You can also receive codes via email — if you have a verified email address on your account, you may be able to use these instead of the authenticator app.
Plan ahead when changing devices — if you know you're getting a new phone, set up the authenticator on the new device while you still have the old one.
Need help?
Contact our Customer Support team and we'll get you back up and running as quickly as possible. Tel: 0330 094 0122
If you get stuck at any point, your office is the best first port of call. You can also reach our Customer Support team — we're always happy to help.
Tel: 0330 094 0122
For anything urgent, please give us a call. For everything else, email works well.

