Configure Multi-Factor Authentication (MFA) Requirements for a Role

Blackbaud requires faculty, admin, and staff users of Blackbaud Education Management® (BBEM) at all schools to use multi-factor authentication (MFA) on their Blackbaud ID (BBID) username and password. These users have security roles with application, employee, or volunteer types.

When enabled for a security role that doesn't log in with

  • single sign-on (SSO),

  • Sign in with Apple ID,

  • or Sign in with Google,

all users in the affected role are required to use Blackbaud's MFA with their BBID.

Note: Users who log in with single sign-on (SSO), Sign in with Apple ID, or Sign in with Google, aren't prompted to use Blackbaud's MFA, even when MFA is required for one of their roles. However, they may be prompted to use an MFA from the identity provider (IdP) instead. For example if your school uses Azure Active Directory (AD) or Google G Suite, those users may use MFA if Microsoft, Apple, or Google are configured to require it.

When MFA is enforced for a user's security role, they must authenticate with two or more verification factors, such as

  • a password and a code received via SMS text message

  • or a password and a code from a mobile authentication app.

Security roles which are constituent or other types are exempt from BBID's MFA enforcement. Thus, users who only have these roles (such as students, alums, parents, and non-administrative users) aren't required to use MFA for their BBID.

Platform managers can choose to require MFA for a security role that's usually exempt. This increases security for the users. If your school chooses to require MFA for a security role that's usually exempt (students, etc.), then a platform manager can also disable the MFA requirement for that role.

  1. Select Core.

  2. Select Security.

  3. Select Roles.

  4. Find the role in the list.

  5. Select the ellipsis (...) at the start of the row. Then configure enforcement:

    • Select Enforce MFA and confirm the change. The next time a user with the affected role attempts to log in, they're prompted to configure and use MFA.

    • Select Remove MFA enforcement and confirm the change. When disabled, users in the affected roles may still be prompted to log in with MFA. However, after logging in, the user can go to their individual BBID profile to opt out of MFA.

Tip: To learn more about MFA or BBID , view the online help.