What we're doing and why.
In response to the security incident that affected Canvas in May 2026, Instructure has launched a comprehensive hardening program. The goal is to build a platform engineered for greater resilience against compromise and accelerated detection of anomalous activity.
One of the first changes you will notice in this program relates to identity and access: phishing-resistant multi-factor authentication (MFA) will be required for admin users across Canvas, Parchment, and Elevate Standards Alignment who use email and password to log in. MFA will also be required for learners accessing Parchment. For Mastery, MFA will be required for all administrators beginning July 30. Admins are able to configure two-step verification for their accounts in advance of that date as well.
MFA is already available as an option in Canvas and Parchment. What's changing is that it's no longer optional for any user with administrative privileges on Instructure products. Admin users carry elevated permissions and are the most attractive target for credential-based attacks. Change to MFA ensures a stolen password alone can’t grant access
Rollout across Canvas, Mastery, and Parchment.
Please note that the following products are excluded at this time. When MFA is enforced, it will be communicated via release or deploy notes and in-app notifications:
- Canvas Studio (edge case where admin is added as a Canvas Studio admin only)
- Elevate Data Quality
- Impact (Legacy)
- Parchment ScribOrder, Scrib Enrollment, ScribOnline, ScribLottery
- Parchment Digital Badges
- LearnPlatform
Who this affects.
This change applies to users with admin-level privileges across Instructure products. It doesn't affect instructors, students, or other non-admin users with the exception of Parchment, which will soon require learners to use MFA.
For Canvas:
- If your institution uses Canvas authentication: Admin users will need to set up MFA. On their next login after enforcement, admins will be prompted to complete setup before continuing — they won't be immediately locked out. MFA can be completed via an authenticator app (Google Authenticator, Authy, and others) or SMS (for US mobile numbers only).
- If your institution uses a third-party SSO or identity provider (Okta, Microsoft, ClassLink, and others): Instructure won't enforce MFA directly. That's managed through your identity provider. We strongly recommend confirming that MFA is enabled and required for admin accounts at the identity provider level. Most higher education and enterprise institutions using SSO already have these capabilities in place.
For Mastery:
- If your institution uses Mastery authentication: Principals and district admins will need to set up MFA. On their next login after enforcement, admins will be prompted to complete setup before continuing — they won't be immediately locked out. MFA can be completed via an authenticator app (Google Authenticator, Authy, and others) or SMS (for US mobile numbers only).
- Admins who want to enable MFA before July 30 can do so by opening the account drop-down menu, selecting Settings, and then selecting Two-Step Verification. Administrators who complete setup in advance will not need to take any additional action after enforcement.
- If your institution uses a third-party SSO or identity provider (Clever, ClassLink, and others): Instructure won't enforce MFA directly. That's managed through your identity provider. We strongly recommend confirming that MFA is enabled and required for admin accounts at the identity provider level.
For Parchment:
- If you are creating a new Parchment account or have an existing Parchment account that does not use SSO to access Parchment: When you create your Parchment account, you will be prompted to verify your email after authentication. After this verification step, you will not be prompted to verify a second time via multi-factor authentication (MFA) in this session. You will be prompted to verify via MFA in all subsequent sessions.
- If your institution uses single sign-on (SSO) to access Parchment: If your organization uses Single Sign-On (SSO) to access Parchment, your login process will not change. Authentication continues through your organization's identity provider.
What you should do now.
- Inventory your admin users across all Instructure products. Know which accounts hold admin-level privileges. Enforcement is coming to all Instructure products except those on the exclusion list above. We also encourage you to use this opportunity to clean up any accounts that no longer require admin privileges.
- Check your native authentication setup. If your institution uses native authentication, prepare your admins for the upcoming MFA prompt. If you use third-party SSO, verify that your identity provider has MFA enabled for admin-level accounts.
- Share this internally. Your IT team and admins across all Instructure products should know this is coming to facilitate a smoother transition.
- Watch for product-specific communications. Admin users will receive a direct in-app notification before enforcement.
Staying informed.
We'll keep trust.instructure.com up to date with the latest. Admin users will receive direct in-app notifications before each product's enforcement takes effect.
Questions? Product-specific support documentation will be available in the community. For institution-specific questions, please reach out to your Instructure Customer Success Manager.