ImmiAccount login problems – how to fix lockouts, password errors, and MFA issues
Migratio Editorial · Last updated
TL;DR: ImmiAccount locks your account for 4 hours after too many failed login attempts. Since 18 June 2025, multi-factor authentication is mandatory, which introduces new failure points. This guide covers password resets, lockout recovery, browser compatibility, MFA errors, and the shared email prohibition in the Terms of Use.
Few things are more stressful than being locked out of your ImmiAccount when you need to check an application status, respond to a Department request, or upload a time-sensitive document. Login problems are among the most frequently reported issues with the ImmiAccount portal, and the causes range from simple typos to browser incompatibilities and the mandatory multi-factor authentication introduced in June 2025. This guide covers the most common login failures, how to resolve each one, and how to avoid getting locked out in the first place.
Account lockout after failed attempts
ImmiAccount enforces an automatic lockout after multiple failed login attempts. Once triggered, your account is locked for 4 hours. During this period, you cannot log in even with the correct credentials. There is no way to manually unlock the account early; you must wait for the lockout period to expire.
The lockout is tied to your username (email address). Common causes include:
- Typing the wrong password multiple times
- Browser autofill inserting an old or incorrect password
- A family member or migration agent attempting to log in with incorrect credentials
- Automated password managers submitting the wrong saved entry
What to do: Stop attempting to log in immediately once you see a lockout message. Note the time, wait the full 4 hours, and try again with the correct password. If you are unsure of your password, use the time to initiate a password reset so a new password is ready when the lockout lifts.
Password reset process
If you have forgotten your password or want to change it after a lockout, use the password reset function on the ImmiAccount login page.
1. Go to online.immi.gov.au and click the "Forgot your password?" link below the login fields.
2. Enter the email address associated with your ImmiAccount.
3. Check your email inbox (including spam and junk folders) for a reset link from the Department.
4. Click the link and follow the prompts to create a new password.
5. Your new password must meet the Department's complexity requirements, which typically include a minimum length, a mix of uppercase and lowercase letters, numbers, and special characters.
The reset email is sent to the address registered on your ImmiAccount. If you no longer have access to that email address, the self-service reset will not work. In that case, you need to contact the Department's technical helpdesk to verify your identity and update your account email.
Common error messages at login
Several error messages appear frequently on the ImmiAccount login screen. Here is what they mean and how to respond.
"Your account has been locked." You have exceeded the failed attempt threshold. Wait 4 hours and try again with the correct credentials.
"Invalid username or password." Either the email address or password is incorrect. Double-check both fields. Remember that the email field is case-insensitive, but the password field is case-sensitive. Verify that Caps Lock is off.
"Your session has expired." You were inactive for too long on the login page or within the portal. Refresh the page and log in again. ImmiAccount sessions time out after a period of inactivity as a security measure.
"System is currently unavailable." The ImmiAccount portal undergoes scheduled maintenance, typically on weekends or during off-peak hours (AEST). The Department sometimes posts maintenance notices on the login page or on its main website. Try again later.
"An unexpected error has occurred." This is a generic server-side error. Clear your browser cache, try a different browser, or wait and retry. If the error persists across browsers and devices, the issue is likely on the Department's end.
Browser compatibility issues
ImmiAccount is a web application that requires a modern browser. Login and portal functionality can break on outdated or unsupported browsers. For the best experience:
- Use the latest version of Google Chrome, Microsoft Edge, Mozilla Firefox, or Safari.
- Avoid using Internet Explorer, which is no longer supported by most modern web applications.
- Enable JavaScript and cookies, as ImmiAccount requires both to function.
- Disable or whitelist ImmiAccount in any ad-blocking or script-blocking browser extensions, as these can interfere with the login form and MFA prompts.
- If you are on a corporate or institutional network, check whether a firewall or proxy is blocking access to online.immi.gov.au or related domains.
Clearing your browser cache resolves a surprising number of login issues. Cached data from previous sessions can conflict with updated login page scripts. In most browsers, you can clear the cache through Settings > Privacy > Clear browsing data.
MFA-related login issues
Since 18 June 2025, multi-factor authentication is mandatory for all ImmiAccount logins. This means that after entering your email and password, you must also provide a one-time code from an authenticator app or SMS. This requirement was extended to EOI (Expression of Interest) and SkillSelect accounts in July 2025.
MFA adds a second layer of security but also introduces new ways the login process can fail:
- Code expired. Authenticator app codes are time-based and typically valid for 30 seconds. If you enter an expired code, the login will fail. Wait for a fresh code and enter it promptly.
- Wrong authenticator account. If you have multiple accounts in your authenticator app, make sure you are using the code for your ImmiAccount, not a different service.
- SMS not received. If you chose SMS-based MFA, delivery delays can occur. Wait a few minutes before requesting a resend. Check that the phone number on your account is current and that your phone has signal.
- Phone lost or replaced. If you no longer have access to the device used for MFA, you will need to go through the MFA recovery process. See the MFA setup and recovery guide for detailed steps.
- Time sync issues. Authenticator apps rely on your phone's clock being accurate. If your device clock is out of sync, the codes will be invalid. Enable automatic date and time in your phone settings.
For a full walkthrough of setting up and recovering MFA, refer to the dedicated MFA setup and recovery article.
Shared email accounts are prohibited
A point that catches some applicants off guard: the ImmiAccount Terms of Use (sections 5.1 and 5.6) explicitly prohibit the use of shared email accounts. Each ImmiAccount must be linked to a unique, individual email address. This means:
- Two people cannot share the same ImmiAccount, even if they are applying for the same visa type.
- Family members must each have their own ImmiAccount with their own email address.
- A migration agent cannot use their own email for a client's ImmiAccount. Sponsor and applicant accounts for partner visas must also be separate, each with its own email address.
If you have been using a shared email address, you risk account access issues and potential violations of the Terms of Use. The Department may restrict or disable accounts found to be in breach.
For partner visa applicants, the sponsor creates their own ImmiAccount and links to the applicant's case using the applicant's Transaction Reference Number (TRN). Both accounts must use separate email addresses.
Frequently asked questions
Can I unlock my ImmiAccount before the 4-hour lockout period ends?
No. The 4-hour lockout is automatic and cannot be shortened by contacting the Department or resetting your password. You must wait for the full period to pass.
I reset my password but still cannot log in. What is wrong?
Make sure you are using the new password, not the old one. Check that your browser is not autofilling the old password. Clear your browser's saved passwords for online.immi.gov.au and enter the new password manually. Also confirm that your MFA step is completing successfully.
I never set up MFA but now the portal demands it. What happened?
MFA became mandatory for all ImmiAccount users on 18 June 2025. If you last logged in before that date, you will be prompted to set up MFA on your next login. Follow the on-screen prompts to enrol your authenticator app or phone number.
Can my migration agent log in to my ImmiAccount for me?
A registered migration agent can be linked to your application, but they should be accessing your case through their own agent portal or their own ImmiAccount, not by logging in with your credentials. Sharing login credentials violates the Terms of Use.
The login page loads but the form fields do not appear. What should I do?
This is typically a browser issue. Try disabling browser extensions (particularly ad blockers and privacy extensions), clearing your cache, or switching to a different browser. Ensure JavaScript is enabled.
Does ImmiAccount work on mobile devices?
ImmiAccount is accessible via mobile browsers, but the portal is optimised for desktop use. Some functions, particularly document uploads and form completion, work more reliably on a desktop or laptop. If you are experiencing login issues on mobile, try a desktop browser to rule out mobile-specific display or compatibility problems.
Compare MARA-registered migration agents — free
Related: ImmiAccount Australia: How to Set Up, Log In and Use the Home Affairs Portal · Connect ImmiAccount to an Authenticator App: Setup, QR Code and Recovery