Does AUSTRAC require MFA on the AUSTRAC Online/reporting account?
Yes, MFA is mandatory for all AUSTRAC Online accounts; users choose between an authenticator app (with 10 recovery codes) or email-based OTP at first login.
Yes. Multi-factor authentication (MFA)is mandatory for all AUSTRAC Online accounts. Every user must set up MFA and a stronger password on first login. There is no opt-out.
MFA method options
Users choose one of two methods:
- Authenticator app — OTP generated by an app such as Google Authenticator or Microsoft Authenticator. AUSTRAC issues 10 recovery codes at setup (single-use, for lost or changed devices).
- Email — OTP sent to the email registered against the user's AUSTRAC Online account. Expires after 5 minutes. The email cannot be a shared address.
One user, one account
Reporting entities cannot share a single login. Each person who needs AUSTRAC Online access must have their own user account, their own non-shared email, and their own MFA configured.