Increase security with multi-factor authentication (MFA)

If you use your email address and password to sign in to your Blackbaud ID through Blackbaud's authentication service, we strongly recommend that you increase security by enabling MFA. And in many cases, Blackbaud enforces MFA on solutions because it's the most effective measure to increase security. However, the optimal authentication for customers is to enforce MFA through a single sign-on (SSO) connection.

What is MFA?

MFA is an authentication method that requires users to identify themselves with two or more pieces of evidence, or factors, when they sign in. The main types of factors are:

  • Knowledge — Something you know, such as such as a password.

  • Possession — Something you have, such as a code sent to a personal device.

  • Inherence — Something you are, such as facial recognition.

When users sign in to their Blackbaud IDs, MFA sends six-digit confirmation codes to their personal devices, and then they provide those codes to confirm their identities before they access Blackbaud solutions.

Why is MFA important?

MFA is the most effective way to increase the security of your Blackbaud account and prevent others from accessing your personal data. Requiring an additional factor for authentication beyond a password significantly increases the costs for attackers and drastically reduces the rate of compromised accounts.

If Blackbaud doesn't enforce MFA on your solutions, then we strongly recommend that you increase security by enabling MFA.

How does MFA work with Blackbaud ID?

When you sign in after MFA is enabled, you must provide a unique confirmation code along with your email address and password. Blackbaud enforces MFA on some solutions, and we recommend that you enable MFA if it isn't enforced. You can receive confirmation codes using a mobile authenticator app or text messages:

To sign in to your Blackbaud ID after you enable MFA, you must provide a unique confirmation code along with your email address and password. Blackbaud enforces MFA on some solutions, and we recommend that you enable MFA even if it isn't enforced. You can receive confirmation codes using a mobile authenticator app or text messages:

  • Mobile authenticators are the most secure method. Unlike text messages, you can receive confirmation codes even if your device is offline or doesn't have cellular service.

  • For text messages on your mobile phone, standard messaging rates apply.

The extra layer of security from MFA means that even if someone obtains your email address and password, they still need a confirmation code to access sensitive data and account information through your Blackbaud ID.

When you enable MFA, you receive:

  • A six-digit confirmation code on your personal device to confirm your identity each time you sign in.

  • A 24-digit recovery code for one-time use that allows you to access your Blackbaud account if you lose your personal device or if you can't receive confirmation codes for any reason.

If Blackbaud doesn't enforce MFA, individual users decide whether to turn on MFA. Admins don't control this decision. For admins to enforce MFA, they must establish an SSO connection and manage MFA through that connection.