Why am I seeing this?
The Los Angeles County Office of Education (LACOE) now requires that all districts and users have 2-Step Verification (2FA) enabled on their Google account. Even though you sign in through Okta with MFA, Google keeps a separate "2-Step Verification" switch that must be turned on to meet this requirement. If it's off, you'll get an Access Denied error at sign-in. The steps below resolve it.
You will not need a new second factor. Because you already use Okta MFA, Google accepts that verification automatically. You're just flipping the switch to "on" — no new phone, authenticator, or security key required.
Step-by-step
- Open your security page. Signed in to your AUSD account, go to https://myaccount.google.com/security. Confirm the top-right profile shows your @ausd.us account.
- Find "2-Step Verification." Under "How you sign in to Google," click the 2-Step Verification tile (it reads "off").
- Turn it on. Click the blue "Turn on 2-Step Verification" button. Ignore the list of "second steps" — you don't need to pick one.
- Let Google recognize your Okta MFA. If prompted, confirm using your normal Okta sign-in. You should not be asked to add a phone or authenticator.
- Confirm. The page will show "2-Step Verification is on." Return to the system that gave the error and sign in again.
Troubleshooting
Still "Access Denied"? Sign out, close the tab, wait ~1 minute, sign back in.
Asked to add a phone/authenticator? Not required for district access — skip it, or contact the Help Desk.
Unsure which account? The top-right profile must show your @ausd.us email; switch accounts if it shows personal Gmail.
Notes for IT / Help Desk
- The requirement comes from LACOE and is enforced via a Google-side 2SV flag, separate from Okta. Okta satisfies the second factor, but the Google 2SV switch must still be enabled per user.
- Because the domain is federated to Okta, users don't enroll a new Google factor.
- Path: myaccount.google.com/security → "How you sign in to Google" → 2-Step Verification → Turn on.
- If the option is greyed out/missing, check the user's OU allows self-managed 2SV and no admin enrollment policy is blocking it.
- Changes take a few minutes to propagate — have the user re-authenticate before escalating.

