Summary
- HMRC’s final MFA activation window for remaining tax-agent accounts began on 28 September.
- Accounts will be activated in stages through 15 October, generally around 9am Monday to Thursday.
- The change brings agent accounts into line with MFA already used for individual and organisation Government Gateway accounts.
HM Revenue & Customs has begun the final phase of its multi-factor authentication rollout for tax-agent Government Gateway accounts, extending a control already used on individual and organisation accounts to the remaining agent population.
HMRC said the final activation window started on 28 September and will run until 15 October. Accounts not already moved to MFA will be activated during that period.
The department says activations will generally take place at around 9am from Monday to Thursday, although individual agents will not receive a specific activation date in advance.
Once enabled, MFA requires an additional verification step alongside the existing sign-in process. The objective is to reduce the value of stolen passwords by requiring an attacker to satisfy another authentication factor before gaining access.
Agent accounts are a particularly important identity boundary because professional tax advisers can act for multiple clients. Compromise of one account can therefore create broader exposure than the loss of a single taxpayer login, depending on the permissions and services available to that user.
The rollout also highlights the operational side of authentication changes. MFA improves account security, but deployment can disrupt established working practices if administrators, shared processes, recovery methods, or contact details have not been prepared in advance.
HMRC has advised agents to review available verification methods, update outdated MFA settings, and check administrator roles. Those steps are intended to reduce service disruption as accounts are moved through the final activation window.
Identity controls have become a recurring focus across both public and private digital services because credential theft remains useful to attackers even where application vulnerabilities are well managed. MFA does not prevent every form of account takeover — phishing, session theft, social engineering, and weak recovery processes can still undermine authentication — but it changes the conditions required for a stolen password to become a successful login.
The Government Gateway is used across a large number of UK tax and public-service interactions, making changes to its access model operationally significant even when they are not responses to a specific cyber incident.
The final phase is therefore less a new security policy than the completion of an identity-control programme. Once the window closes, tax-agent accounts will have broadly the same additional authentication requirement already applied elsewhere in the Gateway environment.




