top of page

UK Home Office Rolls Out Mandatory Multi-Factor Authentication for Sponsor Licence Users

Writer: Xavi
Xavi
1 day ago
4 min read

Updated: 10 hours ago

LONDON, September 22, 2026 — The Home Office has begun switching the Sponsorship Management System (SMS) to compulsory multi-factor authentication, a change that will also retire the Level 2 User role entirely.

The rollout started on 3 September 2026 and is being staggered by cohort rather than applied to everyone at once. The Home Office expects every sponsor to be using MFA by November 2026.

UK SMS mandatory multi-factor authentication 2026 infographic showing phased rollout from September 3, full rollout by November, Level 2 User role abolished from September 9, deactivation deadline March 8 2027, and key actions for sponsors including reviewing user details and maintaining Level 1 access.
UK Home Office rolls out mandatory MFA for SMS users as Level 2 User role is abolished


Rollout Schedule

Cohort

Timing

Existing sponsors

Onboarding began 3 September 2026. Most Work sponsors were told their activation date by 18 September. Study sponsors and the remainder will be notified by early November.

New licences

MFA switched on automatically for licences granted from 9 September 2026 onward.

Rather than flipping a single switch, the Home Office is assigning existing sponsors to onboarding groups and notifying each one individually. Sponsors who have not yet received a date should watch their registered contact channels.

Level 2 Role Being Retired

The bigger structural change sits alongside MFA: the Level 2 User function is being phased out.

Milestone

Date

No new Level 2 Users can be appointed

9 September 2026

Deadline to convert or deactivate existing Level 2 Users

8 March 2027

Home Office deactivates any remaining Level 2 accounts

After 8 March 2027

Level 2 Users who still need access should be upgraded to Level 1 where they qualify. Those who no longer require access should be deactivated before the deadline.

What Sponsors Should Be Doing

The Home Office has framed the MFA launch as a prompt to tidy up SMS user arrangements generally — not just to update login habits.

Verify user records. Level 1 Users need an accurate date of birth, mobile number, and email address on file. Level 2 Users need a valid email address. Without these, users risk losing access once MFA applies.

Budget time for corrections. Changes that do not update automatically in SMS — a date-of-birth amendment being the clearest example — can take up to 18 weeks to process. Where a correction is still pending when MFA activates, the Home Office suggests the Level 1 User switch to email delivery for their one-time passcode in the meantime.

Audit Level 2 access now. Sponsors should identify which Level 2 Users genuinely need continued access, confirm whether they meet Level 1 criteria, and complete upgrades or deactivations well ahead of March 2027.

Watch for dormant accounts. An account untouched for 12 months or more is treated as inactive. If the Home Office flags an inactive Level 1 User, that person has three months from the point of contact to log in and confirm or update their details.

Never drop below one Level 1 User. A sponsor must have at least one eligible Level 1 User for the entire life of its licence. If the inactive-user process leaves a sponsor with none, the licence is suspended and the sponsor has 28 days to nominate a replacement. Failing that, revocation normally follows.

How the Authentication Works

Once enabled, SMS users must supply a one-time passcode on top of their usual username and password.

User

Passcode Delivery

Level 1 User with a valid mobile number

SMS text

Level 1 User without a mobile number

Registered email

Existing Level 2 User

Registered email

A valid date of birth is also required when a Level 1 User first signs in via mobile, and in some situations when contact details are changed.

Lockout Rules

Trigger

Lockout

Incorrect date of birth entered three times

24 hours

Invalid passcode entered three times

20 minutes

Credential Sharing Is Now a Revocation Risk

The updated Sponsor Guidance is explicit: SMS users must not share their password or their MFA passcode with anyone else. The Home Office lists this as a circumstance that can lead to revocation of the sponsor licence.

Authorising Officers, who remain accountable for SMS user activity, should also ensure Certificates of Sponsorship are reviewed at least monthly, as recommended in the guidance.

Quick Reference Summary

Aspect

Details

System

Sponsorship Management System (SMS)

Change

Mandatory multi-factor authentication

Rollout start

3 September 2026

New licences

MFA from 9 September 2026

Full rollout target

November 2026

Level 2 appointments stop

9 September 2026

Level 2 conversion/deactivation deadline

8 March 2027

Inactive account threshold

12 months

Licence suspension risk

No active Level 1 User → 28 days to nominate

Credential sharing

Grounds for revocation


Read Also

Official Resources

Resource

Link

UK Home Office – Sponsor Guidance

Sponsorship Management System (SMS)

Home Office – SMS User Guidance

For the latest immigration updates, visa policy changes, and 2026 developments worldwide, visit: visasupdate.com/blog/category/uk

VisasUpdate.com – The world's most trusted visa intelligence hub.Unlock 2026 immigration breakthroughs, digital nomad policies, and real-time fee alerts—all in one place.

Bookmark us now: visasupdate.com/news – Stay ahead.

 
 
 

Comments


bottom of page