Connect ImmiAccount to an Authenticator App: Setup, QR Code and Recovery

Migratio Editorial · Last updated

TL;DR: ImmiAccount has required multi-factor authentication (MFA) on every login since 18 June 2025. There are two methods: an authenticator app (scan a QR code, or type in the shared secret key if you can't scan it) or an email token sent to your verified email address and valid for 15 minutes — there is no SMS/text-message option. To connect an authenticator app, open it, add a new account, and scan the QR code shown in ImmiAccount's Multi-factor authentication screen. If you lose access to your authenticator app, use the "I cannot use my multi-factor authentication" link on the ImmiAccount login page, or call the Global Service Centre on 131 881 (within Australia) or +61 2 6196 0196 (from outside Australia).

Since 18 June 2025, every login to ImmiAccount requires multi-factor authentication. This is not optional. Whether you are checking an application status, uploading documents, or managing your profile, you will need to verify your identity with a second factor after entering your password. This article walks through connecting ImmiAccount to an authenticator app step by step, the QR code and shared-secret-key methods, how to change your authentication method, and what to do if you lose access to your device.

Why MFA is now mandatory

The Department of Home Affairs made MFA mandatory to reduce unauthorised access to immigration accounts. ImmiAccount holds sensitive personal information including passport details, health declarations, financial records, and visa application history. A compromised account could allow a third party to view, modify, or withdraw applications.

Prior to June 2025, MFA was available but optional. The shift to mandatory enforcement means that any account without MFA configured is prompted to set it up at the next login. You cannot bypass or defer this step.

Your two options: authenticator app or email token

ImmiAccount's own Multi-factor Authentication Quick Reference Guide sets out exactly two ways to complete the second factor — there is no SMS/text-message option, whatever older guides say:

Authenticator app (TOTP). You install an authenticator app — Home Affairs lists Microsoft Authenticator, Google Authenticator, LastPass Authenticator and Duo Mobile as free examples, and any standard authenticator app works. The app generates a six-digit, time-based one-time code (TOTP) that changes every 30 seconds and works without an internet connection once installed.

Email token. A six-digit code is emailed to the verified email address on your ImmiAccount and stays valid for 15 minutes. Home Affairs' own guidance is explicit that this is the less secure option — "we prefer you to use app authentication as it gives you increased protection against data theft, cybercrime and hacking, fast, reliable access, without needing to wait for an email to arrive" — and recommends selecting it only if you genuinely can't use an app (no smartphone, or you don't want one installed).

A desktop option exists too: KeePass can be used as a PC-based authenticator if you don't want to use a phone, though Home Affairs notes this needs a degree of technical ability.

How to connect ImmiAccount to an authenticator app (step by step)

1. Log in to ImmiAccount at online.immi.gov.au with your username and password.
2. On the "Setting up your multi-factor authentication" screen, choose "I am new to this and need to install an authenticator app" if you don't have one yet, or "I already have an authenticator app" if you do.
3. If you need to install one: open your device's app store (App Store on iOS, Google Play on Android), search for an authenticator app such as Microsoft Authenticator or Google Authenticator, and install it.
4. Open the authenticator app and tap the "+" icon or "Add account."
5. ImmiAccount will show a QR code on the "Scan or enter a code" screen. Point your authenticator app's scanner at the QR code to connect it.
6. Can't scan it? ImmiAccount also displays a shared secret code underneath the QR code — type this into your authenticator app manually instead, exactly as shown.
7. Your authenticator app will start generating a six-digit code. Enter the current code into the "Enter your 6 digit code" field on ImmiAccount.
8. Submit. Once accepted, MFA is active and every future login will ask for a fresh six-digit code from the app.

From this point, logging in is a two-step process: enter your username and password, then enter the code your authenticator app is currently showing.

Setting up email token authentication instead

If you don't want to use an authenticator app, choose "Help – I need another option" on the MFA setup screen, which selects email authentication.

1. On the setup screen, select "Help – I need another option."
2. Confirm you want email authentication (ImmiAccount will show a warning that it's less secure than an app).
3. Select "Send code." A six-digit code is emailed to the address verified on your ImmiAccount.
4. Enter the six-digit code within 15 minutes, before it expires.
5. Submit. The "Email authentication has been enabled" confirmation screen displays.

Every future login sends a fresh code to that email address, so you need reliable access to that inbox to log in at all. If your email provider is filtering the Department's messages, check your junk or spam folder before assuming the code hasn't arrived.

How to change your authentication method

You can switch between an authenticator app and email token at any time. Log in to ImmiAccount, open "Manage my ImmiAccount," and select the "Multi-factor authentication" tab. From there, choose "Change authentication method" and follow the setup steps for whichever method you're switching to — you'll need to complete your current MFA method first before the new one takes effect.

Lost your phone or can't access your authenticator app?

This is the scenario most people searching for this page are dealing with. ImmiAccount has two built-in recovery routes, before you need to contact anyone:

1. On the ImmiAccount login page itself, there is a link reading "I cannot use my multi-factor authentication" next to the sign-in form — use this if you're locked out entirely.
2. On the authenticator-app code entry screen specifically, there's a "reset your account authentication" link for when you no longer have access to the app that was generating your codes.

Either path lets you re-set up MFA — typically by falling back to email token authentication (since you still control your email even without your old phone) and then, once you're back in, reconnecting a new authenticator app if you prefer that method.

If neither self-service link resolves it — for example, you've also lost access to the verified email address — call the Department's Global Service Centre on 131 881 within Australia, or +61 2 6196 0196 from outside Australia, and they can help re-verify your identity and reset your account access.

Troubleshooting common MFA problems

Six-digit code rejected as invalid. This is almost always a clock issue, not a wrong code. Authenticator apps generate a TOTP code from your device's clock, and if the phone's date and time are off — even by a minute — the code won't match. Turn on automatic date and time in your device settings and try again.

Can't scan the QR code. If your device's camera doesn't work or you don't want to use it, type the shared secret code shown underneath the QR code into your authenticator app manually — Home Affairs' own guidance treats this as a normal, supported alternative, not a workaround.

Email token not arriving. Check that your email provider isn't blocking or filtering messages from the Department, and check your junk/spam folder. The code is only valid for 15 minutes, so a code you find later has already expired — select "I have not received an email" or request a new one.

Don't have a smartphone at all. Email token authentication doesn't need a phone — use "Help – I need another option" during setup. A PC-based option (KeePass) also exists if you'd rather not use a phone.

Multiple authenticator entries after resetting. If you reset and reconnect an authenticator app, delete the old ImmiAccount entry from the app first — only the most recently connected entry will generate codes ImmiAccount accepts.

Keeping your MFA secure

- Never share your six-digit code with anyone, including someone claiming to be from the Department — Home Affairs will never ask you for it.
- Don't screenshot your QR code or shared secret key and store it somewhere unsecured; anyone with it can connect their own authenticator app to your account.
- Prefer the authenticator app over email token where you can — it's the option the Department itself recommends as more secure.
- If you suspect your account has been compromised, change your password and reset your MFA through the "Change authentication method" screen immediately.

Frequently asked questions

How do I connect ImmiAccount to an authenticator app?

Log in, choose the authenticator app option on the MFA setup screen, install an app like Microsoft or Google Authenticator if you don't have one, open it, tap "+" or "Add account," and scan the QR code ImmiAccount displays. If you can't scan it, type the shared secret code shown underneath into the app instead.

How do I add ImmiAccount to an authenticator app I already have?

Open your existing authenticator app, tap "+" or "Add account," then scan the QR code on ImmiAccount's "Scan or enter a code" screen (or manually enter the shared secret code if scanning doesn't work). Enter the six-digit code the app then generates back into ImmiAccount to finish.

Where do I find the ImmiAccount authenticator QR code?

It appears on the "Scan or enter a code" screen during MFA setup, or when you choose to change your authentication method from Manage my ImmiAccount → Multi-factor authentication. A shared secret code is shown underneath it for manual entry if you can't scan it.

How do I change my ImmiAccount authentication method?

Log in, go to "Manage my ImmiAccount," open the "Multi-factor authentication" tab, and select "Change authentication method." You'll need to verify with your current method first, then follow the setup steps for the new one.

Does ImmiAccount support SMS/text message authentication?

No. As at Home Affairs' own MFA guidance, ImmiAccount offers exactly two methods — an authenticator app or an email token — and no SMS option. If you've read elsewhere that SMS is available, that's out of date.

What do I do if I lose the phone with my authenticator app on it?

Use the "I cannot use my multi-factor authentication" link on the ImmiAccount login page, or the "reset your account authentication" link shown on the code-entry screen — either lets you fall back to email token access. If you've also lost access to your verified email, call the Global Service Centre on 131 881 (Australia) or +61 2 6196 0196 (overseas).

How long does an ImmiAccount email authentication code last?

15 minutes. If it expires before you enter it, select "I have not received an email" or repeat the send-code step to get a fresh one.

Can my migration agent set up MFA on my behalf?

Your migration agent should not have access to your ImmiAccount login credentials. MFA must be set up by you, the account holder, on your own device or email. Sharing credentials or MFA access with another person is against the Terms of Use.

Compare MARA-registered migration agents — free


Related: ImmiAccount Australia: How to Set Up, Log In and Use the Home Affairs Portal · ImmiAccount login problems – how to fix lockouts, password errors, and MFA issues · How to create an ImmiAccount from scratch · ImmiAccount error messages, system outages, and what they actually mean · What does my ImmiAccount status mean?