What is Two Factor Authentication?

Two Factor Authentication is a process which requires each authorized user to log into FSA systems with two types of information:

Something that you know is the First Factor – your ED User ID and Password

Something that you have is the Second Factor – a TFA token that generates a One Time Password, or "OTP".

The TFA token generates a one‐time security code that is used in conjunction with your ED user name and password. The TFA token must be used for remote access when you are using a personal computer, or a Government Furnished Laptop that has been exempted from PIV Card use.

TFA tokens come in several forms, including "key fob’’ devices, credit card sized tokens, and "soft token" applications ("apps") that run on your mobile device. The Department supports two types of tokens, the physical "key fob" device and the "soft token" app. We recommend using the soft token app if you have a compatible mobile device.

You may only register one TFA token to your ED user ID. Choose the form of token you will be using, and follow the instructions below to set up your token.

PLEASE READ THE ENTIRE DOCUMENT BEFORE PROCEEDING

SOFT TOKEN
(VIP ACCESS FOR MOBILE APP) / PHYSICAL TOKEN

The following instructions will guide you through the process of downloading, installing, and registering a "soft token" app on your mobile device (phone or tablet). The app is a commercial product named VIP Access, provided by Symantec Corporation.
Important Notes:
  • The TFA soft token app (VIP Access) can be installed on a personally owned or government‐furnished mobile device (phone
    or tablet).
  • Before proceeding, find out if your device is supported by the Symantec ID Protection software (VIP Access). VIP Access is available for the ED‐issued Windows Phone and most iOS, Android, Windows, BlackBerry, and BREW‐enabled devices. Visit from your computer to confirm that your device model is listed. If your device is not supported, or you do not wish to use the soft token app, follow the instructions for a physical token.
  • We recommend using Wi‐Fi if possible when downloading the VIP Access app. Carrier charges may apply for download and
    activation. A mobile data plan with Internet access is required. FSA is not responsible for any data charges incurred when downloading the app. Once activated, using the VIP Access app does not transfer any data to or from your device.
Customer Support
For assistance with TFA token registration, Please contact the TFA Support Center at 1‐800‐330‐5947. /
The following instructions will guide you through the process of registering a physical TFA token.
Important Notes:
  • Only physical tokens issued by FSA can be used to access ED/FSA systems.
  • The TFA token must be in your physical possession when you register it, and when you use it tolog into an D/FSA system.
  • The token generates a One Time Password (OTP) that is valid for 30 seconds.
  • To generate the OTP, press the "power" button on the front of the token. Wait until the screen clears before pressing the button for a new OTP.
Customer Support
For assistance with TFA token registration, Please contact the TFA Support Center at 1‐800‐330‐5947
Step 1 – Download and install the VIP Access app
  1. On your mobile device, open a web browser and go to The browser will detect your device and display a download button for the app.
  2. If you don’t see the option to download the app, visit from your computer for additional download options.
  3. Click "Download Now"
  4. Download and install the app on your mobile device.
  5. Open the VIP Access app.
  6. Click "Yes" or "I Agree" to accept the license agreement and activate the VIP Access app.
Continue to Step 2 – Register your soft token / Step 1 – Obtain a TFA token
If you have not already received a physical TFA token, obtain a token from the appropriate person listed below:
  • Department of Education employees and contractors (excluding FSA) – IT POC
  • FSA employees ‐ Business Unit Coordinator
  • FSA contractors ‐ Contractor PM. The Contractor PM receives tokens from the FSA Property Manager.
Continue to Step 2 – Register your token
Step 2 – Register your soft token for use with your ED account
Note: You must be outside the ED Network to register your soft token.
  1. Be sure you have your mobile device available before starting the registration process.
  2. Using a PC or laptop (not your mobile device) that is accessing the internet from outside the ED network, go to the login screen of the application you want to access.
  3. FSA Citrix –
  4. Anywhere.ED.gov –
  5. Fpass –
  6. You will see blank spaces labeled User Name, Password and Security Code; do not enter anything at this time
  7. Click "Register/Maintain Token."
  8. Enter your ED User Name and Password, and click "Log On." This will open the New Token Registration section.
  9. Enter "Step 1 – Profile information"
  10. Enter "Step 2 – Token Serial Number" information
  11. On your mobile device, open the VIP Access app.
  12. Enter the Credential ID displayed on the screen in the Serial Number field. The Credential ID is VSMT or VSTZ followed by 8 digits, e.g., VSMT12345678 or VSTZ12345678
  13. Reenter the Credential ID in the Confirm Serial Number field and click "Submit."

  1. Complete "Step 3 – Challenge and Answer Responses"
  2. Scroll through the "Step 4: Terms of Service"
  3. Click the Checkbox in Step 4 and then click "Submit"
  4. On the Token Security Code Entry Screen, you will be prompted to enter two consecutive security codes to synchronize your token. The security code changes every 30 seconds.
  5. If needed, open the VIP Access app on your mobile device
  6. Enter the Security Code displayed on the screen
  7. Wait until the Security Code changes, and then enter the new Security Code displayed on the screen. Click "Submit."
  8. When the "Success" message is displayed, your soft token is associated with your ED account and is ready for use. Close your browser.

Continue to Step 3 – Use your soft token to access ED/FSA systems / Step 2 – Register your token for use with your ED account
Note: You must be outside the ED Network to register your token.
  1. Be sure you have your token available before starting the registration process.
  2. Using a PC or laptop that is accessing the internet from outside the ED network, go to the login screen of the application you want to access.
  3. FSA Citrix –
  4. Anywhere.ED.gov –
  5. Fpass –
  6. You will see blank spaces labeled User Name, Password and Security Code; do not enter anything at this time
  7. Click "Register/Maintain Token."
  8. Enter your ED User Name and Password, and click "Log On." This will open the New Token Registration section.
  9. Enter "Step 1 – Profile information"
  10. Enter "Step 2 – Token Serial Number" information
  11. Enter the Token Serial Number (S/N) printed on the back of the token in the Serial Number field. The Serial Number is AVT followed by 9 digits, e.g., AVT123456789.
  12. Reenter the Token S/N in the Confirm Serial Number field and click "Submit."

  1. Complete "Step 3 – Challenge and Answer Responses"
  2. Scroll through the "Step 4: Terms of Service"
  3. Click the Checkbox in Step 4 and then click "Submit"
  4. On the Token Security Code Entry Screen, you will be prompted to enter two consecutive security codes (OTPs) to synchronize your token. The security code changes every 30 seconds.
  5. Press the button on your token to generate an OTP. Enter the OTP displayed on the screen in the first box.
  6. Wait until the screen clears, and then press the button to generate a new OTP. Enter the new OTP displayed on the screen in the second box. Click "Submit."
  1. When the "Success" message is displayed, your token is associated with your ED account and is ready for use. Close your browser.

Continue to Step 3 – Use your token to access ED/FSA systems
Step 3 – Use your soft token to access ED/FSA systems from outside the ED network
  1. Using a PC or laptop (not your mobile device), open a web browser
  2. Go to the login screen of the application you want to access:
  3. FSA Citrix –
  4. GoToWork –
  5. Anywhere.ED.gov –
  6. Fpass –
  7. On your mobile device, open the VIP Access app.
  8. On the login screen, enter the following information:
  9. ED user name
  10. Password
  11. Type the Security Code displayed on the screen in the Security Code field (Note: Each security code is valid for 30 seconds. You can see the time remaining in the security code window.)
Click "Log On" and your login will be completed. If the information you entered is valid, you will be granted access to the network. / Step 3 – Use your token to access ED/FSA systems from outside the ED network
  1. Using a PC or laptop, open a web browser
  2. Go to the login screen of the application you want to access:
  3. FSA Citrix –
  4. GoToWork –
  5. Anywhere.ED.gov –
  6. Fpass –
  7. On the login screen, enter the following information:
  8. ED user name
  9. Password
  10. Press the button on your token to generate a Security Code
  11. Type the Security Code displayed on the screen in the
    Security Code field (Note: Each security code is valid for 30 seconds.)
Click "Log On" and your login will be completed. If the information you
entered is valid, you will be granted access to the network.