In a GOV.UK notice, the government said DSCC Online will introduce multi-factor authentication for all users in early September 2026. The change is presented as a security measure intended to reduce the risk of unauthorised access to a service used by legal professionals. For Policy Wire readers, the immediate point is that this is not a minor log-in update. It changes how access is verified, places greater weight on individual account ownership and requires organisations to check that every person using the service can sign in under their own credentials.
According to the notice, multi-factor authentication means users will need more than one form of identification when signing in. In practical terms, a password alone will no longer be treated as sufficient for access, with a second check completed through an authenticator app. The methods listed in the announcement are Microsoft Authenticator and third-party authenticator apps such as Google Authenticator. The notice does not refer to SMS codes or email-based verification, so firms should prepare on the basis that app-based authentication will be the standard route.
A second operational message sits behind the security announcement. The government says all existing users are being contacted to make sure each person has an individual DSCC Online account, and it states clearly that shared accounts are not permitted. That matters for account governance as much as cyber security. Individual accounts make it easier to tie activity to a named user, confirm who holds access at any given time and remove permissions when staff change roles or leave. For legal practices, that creates a clearer record of account use than an office-wide sign-in.
The timetable is also relatively tight. Further information and guidance on the enrolment process is due to be issued ahead of the planned implementation date in early September 2026, which leaves organisations with a limited window to regularise accounts before the change takes effect. The operational risk is straightforward. Firms that leave account checks until the last moment may face avoidable access problems once MFA goes live. Offices with new starters, temporary cover arrangements or long-standing shared log-ins are likely to have the most preparation to complete.
For organisations that need additional accounts created before the roll-out, the notice directs requests to dsccadmin@dutysolicitors.org using the subject line 'MFA - New Account'. The information requested for each user is full name, PIN, email address and office account number. That requirement points to the main administrative task over the coming weeks. Practice managers and system administrators will need to confirm that account records match named individuals, that contact details are current and that any staff member still relying on another person’s credentials is moved onto a separate account.
The broader policy direction will be familiar across public-sector digital services: stronger access control, clearer user attribution and less tolerance for informal workarounds. Even where the immediate effect is only an extra step at sign-in, MFA usually marks a firmer approach to account management. For DSCC Online users, the message from the GOV.UK notice is clear. Each user should expect to enrol an authenticator app, each organisation should ensure that no shared accounts remain in use, and any missing accounts should be requested before the early September 2026 start date.