Summary
- More than 6,000 agents requested early MFA activation before the latest rollout phase.
- The additional authentication applies across accounts held under each selected agent identifier.
- Remaining accounts will move automatically to MFA between 28 September and 15 October.
HM Revenue & Customs has completed the latest phase of its multi-factor authentication rollout for tax agents, with remaining accounts due to move automatically to the stronger login process between late September and mid-October.
Agents who selected 19 August for early activation have now entered the new regime. HMRC previously said more than 6,000 agents had requested early activation, following an earlier July phase.
Once MFA is enabled for an agent identifier, it applies across the accounts held under that ID. Agents with several identifiers were able to select which ones entered earlier phases, while any remaining accounts will be included automatically in the final activation window from 28 September to 15 October.
The programme extends protection already used for individual and organisational Government Gateway accounts. Users continue to enter their Government Gateway ID and password but must then provide an additional one-time access code.
Tax agents represent a particularly important form of external privileged access. One professional account may be used to interact with HMRC on behalf of many clients, potentially connecting a single compromised identity to financial and administrative information belonging to several individuals or businesses.
Additional authentication reduces the value of a stolen password, although it does not eliminate account-takeover risk. Session theft, social engineering and adversary-in-the-middle phishing can allow attackers to work around some MFA implementations, while account-recovery processes can become another route around the primary login control.
HMRC is therefore coupling the rollout with guidance covering administrator roles, authentication settings and suspicious-account activity. Its security console also allows agents with MFA enabled to report unexpected changes or other signs that an online account may have been compromised.
The implementation creates operational considerations for professional firms as well. Some organisations use multiple agent IDs or third-party software in their tax workflows, and HMRC has warned that automated sign-in processes may need adjustment once the additional authentication step becomes mandatory.
Those dependencies demonstrate why identity changes are rarely confined to a login screen. Stronger authentication has to coexist with shared administrative processes, account recovery, software integrations and staff turnover if it is to improve security without prompting insecure workarounds.
The change also coincides with wider reforms requiring more tax advisers to register with HMRC. As professional access becomes more formalised, the identities used to interact with government systems increasingly resemble enterprise privileged accounts: they act on behalf of other parties, carry substantial trust and require controls proportionate to the access they receive.
HMRC cannot give individual activation dates to firms entering the final September-to-October group. Organisations that have not already moved will therefore need to be prepared for authentication to change at any point during that period.
By 15 October, the remaining agent accounts covered by the programme should be operating under MFA. The programme is a relatively conventional security measure, but its reach across delegated professional access makes the quality of implementation more consequential than the familiarity of the control itself.




