Summary
Beginning September 14, 2026, new FHA Connection users must complete a one-time identity-proofing process before gaining system access. FHA says the process will require personally identifiable information, a government-issued credential and a biometric comparison using a selfie.
Mortgage professionals seeking new access to one of the Federal Housing Administration’s most important technology systems will soon have to prove they are who they say they are—and that will include submitting a selfie.
Beginning September 14, new users of FHA Connection will have to complete a one-time identity-proofing process before HUD grants them access to the system, according to FHA INFO 2026-20, issued September 8.
The verification will require personally identifiable information, a government-issued credential and what FHA calls a “biometric comparison”—specifically, a selfie used to validate the user’s identity.
FHA says the change is intended to reduce cyber risk and fraud while protecting government resources.
For mortgage companies and other organizations whose employees need FHA Connection access, however, the announcement also signals something broader: HUD is continuing to tighten the identity and authentication requirements surrounding access to federal housing systems.
What changes September 14
The immediate requirement is relatively straightforward.
A person requesting new FHA Connection access will have to complete identity proofing before receiving access.
According to FHA, that process requires three basic elements:
- Personally identifiable information;
- A government-issued credential used for document verification; and
- A biometric comparison using a selfie to validate the person’s identity.
This is a one-time identity-proofing process for new users—not a requirement to take a selfie every time someone signs into FHA Connection.
That distinction is important.
FHA Connection already has separate authentication requirements governing how authorized users sign into the system. The new process adds identity proofing before system access is initially granted.
FHA says the initiative is designed to align its system with the federal government’s Enterprise Identity, Credential, and Access Management mandate and National Institute of Standards and Technology best practices.
Why FHA Connection matters
FHA Connection isn’t simply an informational website.
It is part of the operating infrastructure behind FHA’s Single Family mortgage-insurance program.
HUD describes FHA Connection as a system through which approved lenders and other authorized users perform a range of FHA-related functions.
Among other uses, FHA Connection provides access to the Lender Electronic Assessment Portal, or LEAP, which lenders use for institution and branch profile information and annual recertification. FHA Connection also supports functions associated with FHA mortgage-insurance processing and administration.
HUD’s FHA Connection registration information makes clear that access is tied to individual users and that HUD collects identifying information to verify people requesting access to its systems.
The new identity-proofing process adds another layer to that verification.
This is different from FHA’s existing MFA requirement
There is an important distinction between proving who someone is and proving that the person signing in is the authorized account holder.
FHA has already been moving users toward stronger authentication.
HUD previously implemented phishing-resistant multi-factor authentication for FHA Connection, including Okta FastPass and FIDO2 authentication options. FHA ultimately set January 5, 2026, as the deadline for users to implement the phishing-resistant MFA requirement.
Those measures concern authentication when an authorized user accesses the system.
The September 14 change concerns identity proofing for new users before access is granted.
Put more simply: MFA helps establish that the person attempting to use an account possesses the required authentication factors.
Identity proofing is intended to establish that the person receiving access is actually the individual they claim to be.
The selfie is part of that second process.
The mortgage industry should pay attention to the direction of travel
The immediate operational impact is likely to be most noticeable when lenders, appraisal organizations and other participating entities bring new employees or users into FHA workflows.
Organizations that routinely provision FHA Connection access should make sure employees understand the new requirement before beginning registration.
FHA also used its September 8 notice to tell institutions to review their profiles in LEAP and verify that required approvals are in place and consistent with their level of participation in FHA programs.
The broader significance, however, goes beyond onboarding.
Mortgage companies handle extraordinary amounts of sensitive financial and personal information. Government mortgage systems also provide access to functions capable of affecting federally insured loans and participating institutions.
That makes compromised credentials particularly consequential.
Federal agencies have increasingly moved away from relying primarily on usernames, passwords and conventional authentication toward stronger identity-management standards.
FHA’s new requirement puts biometric identity verification directly into that progression.
What FHA has—and hasn’t—said
The September 8 announcement is specific about what happens next.
New FHA Connection users must complete the identity-proofing process beginning September 14.
The process includes a selfie.
It is one-time identity proofing before access is granted.
FHA says the purpose is to mitigate cyber risk and fraud.
There are also things the announcement does not establish.
FHA does not say that borrowers applying for FHA mortgages must submit selfies as part of their mortgage application.
They do not.
This announcement concerns users seeking access to FHA Connection, not FHA borrowers generally.
Nor does FHA say users will have to provide a selfie every time they log in.
The agency also does not provide enough information in the September 8 notice to establish how long biometric information will be retained, precisely how the biometric comparison will technically operate, or what alternative process will apply if a user’s identity cannot be successfully verified through the standard procedure.
Those are legitimate questions, but WRE News will not assume answers that HUD has not provided.
A small onboarding change with a much larger message
For an individual mortgage professional, the new process may amount to an additional step when obtaining FHA Connection access.
For the industry, the direction is more significant.
FHA has already strengthened authentication for the people using its systems.
Now it is strengthening the process used to establish who those people are before access is granted.
“Beginning September 14, a username, password and institutional authorization won’t be the entire identity story for a new FHA Connection user. HUD wants to see the person behind the credentials, too.”





















0 Comments