In this guide
Access Boston multi-factor authentication adds a verification step to the City account. The City’s Access Boston FAQ describes MFA as a second factor, usually a phone; the City’s welcome guide also describes managing devices and setting up PingID. Use the method shown on your current official account screen. If you can still sign in, use the City’s device-management route; if you have lost the only registered factor, contact the City Service/Help Desk rather than trying to bypass MFA.
This article is about the decision path around a phone change, repeated prompts, and missing verification. It is not a device enrollment screen. Do not enter a code on this publication or send a code to anyone who contacts you unexpectedly.
Understand what the second factor does
A password is something you know; a second factor asks you to prove access to another registered method. The City FAQ explains that MFA is used to make an account harder to access with a password alone. That is why a new phone is not just a cosmetic profile change: the City must recognize a factor associated with the account.
The City’s 2021 welcome guide listed registration methods that included a mobile text, a voice call, or a non-Boston email address, and it described a PingID app option. These are historical examples from a guide revised in 2021. A later configuration may present different choices or may require a specific method. Follow the present City prompt and do not rely on an old screenshot.
WATCH & UNDERSTAND · 36 SECONDS
A safer route when an MFA device changes
Original visual explainer · silent · no autoplay
A silent diagram of safe options when replacing a phone: use official device management while signed in, or contact the City help desk if the registered method is unavailable. Never share a code. This is an editorial illustration, not a provider tutorial or a recording of an account. Video files are served by this website.
Read the full video explanation
- Before replacing a working device, check the current official device options if you can still sign in.
- The City welcome guide describes a Manage My Devices route. Current account prompts determine which methods are available.
- If no registered method works, contact your verified department Service/Help Desk. Do not try to bypass MFA or enroll through another site.
- Keep every verification code private. An editorial guide cannot verify or change your City account.
Source context: Access Boston FAQ (October 2023) · Access Boston welcome information (2021). The visual arrangement and hypothetical examples are editorial explanations.
If you still have access to the old device
Before replacing a working phone, sign in through the official portal and check the available device-management options. The City welcome guide refers to a Manage My Devices link for adding a new phone or email method and says a City-issued device may already have PingID installed. Confirm the current options while the old factor still works, and complete the change using the official screen.
Keep the old method available until the new one has been tested and accepted by the City account. That is a general continuity precaution, not a guarantee that the portal supports simultaneous factors or a particular order. If the account offers only one method, or the device change affects a managed City phone, ask the department help desk before deleting or wiping the old device.
If the old phone is gone
When you cannot receive a code from any registered method, do not use a third-party reset page or try to enroll a new factor through an unrelated application. The public City materials direct employees to a Service/Help Desk for unresolved access questions. Contact the desk through a verified City address or phone number and follow its identity-check procedure.
In your first message, describe that the registered method is unavailable and say which official step you can reach. Do not include the one-time code, a recovery secret, or a full account screenshot. The help desk may need to route the request to the Access Boston team; an editorial publisher cannot verify your identity or change MFA settings.
Repeated code prompts and browser storage
The City FAQ, last updated October 2, 2023, says users may be asked for a new code repeatedly when the browser clears cookies at the end of every session. It also notes that blocking all cookies can interfere with the session countdown. If this matches your experience, check the browser’s site-specific privacy settings for the official City portal and ask IT for help. Avoid lowering protection across every website just to change one setting.
A browser can also be private or managed by department policy. If settings are locked, do not install an extension or change device-management controls to work around them. Provide the service desk with the browser name, approximate version if easy to find, and the fact that the prompt repeats after each session. Keep the actual code private.
Before replacing or resetting a device
- Confirm the current City-supported MFA method in an official source or account screen.
- If possible, register and test the replacement factor before removing the working one.
- If you cannot sign in, use the verified department Service/Help Desk; do not attempt a bypass.
- After the change, update only the device or contact method that the official account process requests.
For initial account registration, see the new employee setup guide. If sign-in itself fails for a different reason, use the Access Boston troubleshooting route. The main guide identifies the official portal and the difference between an account prompt and an application-specific issue.
Official sources and limits
- Access Boston FAQ (updated October 2, 2023)
- Access Boston welcome information (revised May 4, 2021)
- Access Boston Portal Help
Source check: 2026-09-27. The cited City documents have different publication or revision dates; time-sensitive instructions are identified in the guide. Follow the current official portal or your department’s instructions if they differ.