What changed
- A second check for admin accounts. Admins and account managers confirm it’s really them with a short code before Pria lets them in. A stolen or guessed password is no longer enough.
- Canvas can’t sign an admin in silently. When a Canvas page opens Pria for an admin account, Pria stops and asks for the code first.
- Only the right people get admin rights. A Digital Twin created from a Canvas course must be confirmed by its contact person (with an email code) before they can administer it. Organisation sign-in (SSO) only signs in people who are already members.
- Sensible limits. Codes expire quickly, wrong attempts are limited, and a trusted device stays trusted only on the network where it was verified.
Who is asked for a code
You are not asked again when:
- you verified on this device in the last 24 hours inside Canvas (7 days in a normal browser tab), on the same network; or
- your Digital Twin uses Authenticate with Canvas — the Canvas sign-in itself counts as the second check.
Switching to a new network (a different Wi-Fi, a VPN) means a new code, even on a trusted device.
What you will see in Canvas
1
Pria asks to confirm it's you
You open a Canvas page where Pria is embedded. Pria’s panel shows Confirm it’s you instead of the usual view — right there in the page. No new tab, no pop-up.
2
Send me a code
Click Send me a code. Pria emails a 6-digit code to the address on your account. Nothing is sent until you click, so you won’t get an email on every Canvas page.
3
Type the code
The code is valid for 5 minutes. After 5 wrong tries you’ll need to request a new one (allow 30 seconds between requests).
4
Carry on
Pria continues where it left off, and remembers this device on this network for 24 hours.
If something goes wrong
"Account temporarily locked"
"Account temporarily locked"
Too many wrong codes (10 in an hour, or 20 in a day). Wait the time shown, or ask an admin to clear it.
No access to your email, authenticator or backup codes
No access to your email, authenticator or backup codes
An admin opens Admin → Users, edits your user and, on the Security tab, turns off Require email MFA for this user. That resets your second factor and trusted devices; your next sign-in goes straight through, and you can set two-step verification up again from your profile.
Asked for a code on every Canvas page
Asked for a code on every Canvas page
Your browser is blocking storage for embedded sites (private browsing, or strict cookie settings). Pria still works; allow site data for Pria, or use a normal window.
Checklist for Digital Twin admins
- Tell your admins and account managers to expect the Confirm it’s you step in Canvas, and to use the email address on their Pria account.
- If you want the code check for a specific admin, turn it on under Admin → Users (the Security tab).
- If your Digital Twin already requires Authenticate with Canvas, your admins will not see an extra prompt.
Related
- Multi-Factor Authentication (MFA) — managing two-step verification for your users
- Access your LMS — connecting Pria to your LMS account
- Custom Theme — how Pria is embedded in Canvas