You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
close
You are viewing the article in preview mode. It is not live at the moment.
Home > Miscellaneous > LACOE BEST 2FA ERROR MESSAGE FIX
LACOE BEST 2FA ERROR MESSAGE FIX
print icon

Why am I seeing this?

The Los Angeles County Office of Education (LACOE) now requires that all districts and users have 2-Step Verification (2FA) enabled on their Google account. Even though you sign in through Okta with MFA, Google keeps a separate "2-Step Verification" switch that must be turned on to meet this requirement. If it's off, you'll get an Access Denied error at sign-in. The steps below resolve it.

You will not need a new second factor. Because you already use Okta MFA, Google accepts that verification automatically. You're just flipping the switch to "on" — no new phone, authenticator, or security key required.

Step-by-step

  1. Open your security page. Signed in to your AUSD account, go to https://myaccount.google.com/security. Confirm the top-right profile shows your @ausd.us account.
  2. Find "2-Step Verification." Under "How you sign in to Google," click the 2-Step Verification tile (it reads "off").
  3. Turn it on. Click the blue "Turn on 2-Step Verification" button. Ignore the list of "second steps" — you don't need to pick one.
  4. Let Google recognize your Okta MFA. If prompted, confirm using your normal Okta sign-in. You should not be asked to add a phone or authenticator.
  5. Confirm. The page will show "2-Step Verification is on." Return to the system that gave the error and sign in again.

Troubleshooting

Still "Access Denied"? Sign out, close the tab, wait ~1 minute, sign back in.
Asked to add a phone/authenticator? Not required for district access — skip it, or contact the Help Desk.
Unsure which account? The top-right profile must show your @ausd.us email; switch accounts if it shows personal Gmail.

Notes for IT / Help Desk

  • The requirement comes from LACOE and is enforced via a Google-side 2SV flag, separate from Okta. Okta satisfies the second factor, but the Google 2SV switch must still be enabled per user.
  • Because the domain is federated to Okta, users don't enroll a new Google factor.
  • Path: myaccount.google.com/security → "How you sign in to Google" → 2-Step Verification → Turn on.
  • If the option is greyed out/missing, check the user's OU allows self-managed 2SV and no admin enrollment policy is blocking it.
  • Changes take a few minutes to propagate — have the user re-authenticate before escalating.

 

 

Feedback
0 out of 0 found this helpful

scroll to top icon