Share:

Multi-factor authentication

Multi-factor authentication (MFA) has been introduced for users who log in via the website. It will not apply to B2G requests or managing secured party groups once you have logged in.

On this page

Getting started with MFA

MFA has been introduced on the PPSR for users logging via the website.

It adds an extra step when signing in to the PPSR, helping prevent unauthorised access, reducing the risk of fraud or unauthorised changes, and providing stronger protection for users.

MFA is mandatory for all users from 1 October 2026.

How to use MFA

When you log in, the PPSR will send a one-time passcode (OTP) to the email address recorded on your user profile.

  • The OTP will be 6 digits and is valid for 5 minutes.
  • When you enter a valid OTP, you will have your usual access to the PPSR.
  • If you enter an invalid or expired passcode several times, you will be suspended for a short period. Another user, including AFSA’s Service Centre, cannot assist with access while you are suspended.
  • If you don’t receive the OTP, you can resend a new one after one minute.
  • If you have resent the OTP three times, you will have the option to use another method.
  • If the PPSR has a known issue with emails, you will be able to use the other method without resending the OTP.
  • If you enter incorrect details on the alternative method, your user profile will automatically be locked.

Please note: If your password is expired or due to expire, you will be prompted for a new password after you have completed MFA.

When MFA is not needed

You only need to use MFA when you login with your username and password on the PPSR. This means once you are logged in, you don’t need to use MFA when you:

  • connect via B2G
  • use a new user or password reset link

Once you have logged in to the PPSR, you will not need to use MFA again to complete further tasks. This includes the following transactions:

  • updating your own password or secret questions
  • managing your account
  • managing your secured party group
  • managing your registrations
  • requesting a report.

Access codes and tokens will still need to be used where required.

Account administrators: prepare your users for MFA

What you can do

Account administrators are encouraged to review their users.

If someone is no longer with your organisation, we would recommend deactivating or remove their access. Use the user management report to review users in your account and their registered email address. For information about running this report, see Getting PPSR reports. 

Review shared credentials

  • Shared email address: If several users use the same email address, this can cause confusion with the OTP codes.

Each OTP email will include the username in the subject line and the first name in the email body to help identify the correct code.

To avoid confusion and potential access issues, each user should have their own unique username and individual email address when accessing the PPSR.

  • Shared usernames: The PPSR does not recommend the use of shared usernames. Multiple users entering incorrect one-time passcodes can suspend the user.

There is no limit to the number of users or account system administrators you can have attached to your account. It is recommended each user has their own username with individual names and email addresses recorded.