SMS Authentication (MFA) (2024)

The SMS Authentication factor allows users to authenticate themselves using a one-time passcode (OTP) that is delivered to their phone in an SMS message.

There are important considerations that you must be aware of when using telephony as part of your multifactor authentication strategy, including regulatory requirements, toll fraud, and others. See Telephony for more information.

There are also important technical considerations for sending SMS messages. See Configure and use telephony for more information.

You can also customize SMS message templates, view SMS events in the System Log and view SMS usage reports. See Configure and use telephony for more information.

Using phone OTP isn't a guaranteed way to verify a user's identity. See Potential risks of verifying identity through SMS and voice call.

Okta recommends that you require users to authenticate using a more robust authenticator. For example, an authenticator that not only verifies the user presence but is also device-bound, hardware-protected, or phishing-resistant. Such authenticators include authenticator apps, email magic links, or FIDO2 (WebAuthn). See MFA factor configuration.

Toll-free, premium, and invalid phone numbers can't be used for multifactor authentication. If you attempt to use a toll-free, premium, or unrecognized phone number format, the phone number is rejected as an invalid phone number.

Okta recommends that admins enable other factors in addition to the SMS Authentication factor. This gives users additional verification options. If an end user changed their phone number and didn't update it in Okta, voice calls and SMS messages are sent to the old number. Users need alternate verification methods to enable them to sign in to Okta so they can update their phone number.

Before you begin

  • Connect to an external telephony service provider using either Okta Workflows or Okta API. For guidance about selecting a telephony service provider, see Choose telephony provider.
  • Review Telephony documentation to understand regulatory requirements, toll fraud, and technical considerations.

Activate the SMS Authentication factor

  1. In the Admin Console, go to SecurityMultifactor.

  2. On the Factor Types tab, select SMS Authentication.
  3. Click Inactive and select Activate.
  4. Click the Factor Enrollment tab.
  5. Select a policy from the list and click Edit. Or, to create a factor enrollment policy, click Add Multifactor Policy, and follow the instructions in Configure an MFA enrollment policy.
  6. Select the dropdown list beside SMS Authentication and select an option:
    • Optional - Users may select the SMS Authentication factor from the list and use it to authenticate.
    • Required - Users must provide an OTP they receive in an SMS message when they authenticate.
    • Disabled - Users aren't asked to authenticate with an OTP they receive in an SMS message.
  7. Click Update Policy.

End-user experience

When this factor is activated, users signing in to Okta for the first time see that extra verification is required.

Set up the SMS Authentication factor for the first time

  1. While signing in, the Sign-In Widget displays the Set up multifactor authentication page.
  2. Click Configure factor.
  3. Select the country that your phone number is from in the Country dropdown list.
  4. Type your phone number in the Phone number field. Don't include the country code, leave out any dashes, and leave out the leading zero if your country's phone system uses them.
  5. Click Send code. You receive a code in an SMS message.
  6. Type the code in the Enter Code field.
  7. Click Verify.

Sign in with the SMS Authentication factor

  1. Go to your org's sign-on page. Provide your username and any other credentials requested by the Sign-In Widget, such as a password.

  2. Click the down arrow and select SMS Authentication from the Select an authentication factor list.

  3. Okta sends an SMS message, and the Sign-In Widget displays the Enter Code field. If you don't receive the code automatically, click Send Code.

  4. Type the code provided in the SMS message in the Enter Code field.

  5. Click Verify.

If you changed your phone number and haven't updated it in Okta yet, voice calls and SMS messages go to your old phone number and you can't complete verification. If this happens, click Sign in with something else on the Sign-In Widget, and verify with a different factor. Next, complete the Change the phone number for the SMS Authentication factor procedure, and replace your old phone number with your new one.

Change the phone number for the SMS Authentication factor

Users can change the phone number to which OTP codes are sent by removing the SMS Authentication factor and then setting it up again.

  1. In the Okta Dashboard, click your username in the upper-right corner.
  2. Select Settings.
  3. In the Extra Verification section, click Remove beside SMS Authentication, and click Yes to confirm.
  4. Click Set up beside SMS Authentication.
  5. Continue with the steps in Set up the SMS Authentication factor for the first time.

Related topics

Voice Call Authentication (MFA)

Telephony

Configure and use telephony

SMS Authentication (MFA) (2024)
Top Articles
What is Discounted Cash Flow (DCF)? Formula and Examples
Can you Transfer iTunes Credit? 3 Support Alternatives
How To Start a Consignment Shop in 12 Steps (2024) - Shopify
Jail Inquiry | Polk County Sheriff's Office
Mchoul Funeral Home Of Fishkill Inc. Services
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Alpha Kenny Buddy - Songs, Events and Music Stats | Viberate.com
His Lost Lycan Luna Chapter 5
Culver's Flavor Of The Day Monroe
Craigslist Dog Kennels For Sale
Best Restaurants Ventnor
Springfield Mo Craiglist
Non Sequitur
Letter F Logos - 178+ Best Letter F Logo Ideas. Free Letter F Logo Maker. | 99designs
Patrick Bateman Notebook
Carolina Aguilar Facebook
Happy Life 365, Kelly Weekers | 9789021569444 | Boeken | bol
Craigslist Org Appleton Wi
Employee Health Upmc
Shadbase Get Out Of Jail
Southland Goldendoodles
Asteroid City Showtimes Near Violet Crown Charlottesville
Jesus Revolution Showtimes Near Regal Stonecrest
Hdmovie2 Sbs
4Oxfun
Villano Antillano Desnuda
Danielle Moodie-Mills Net Worth
Keshi with Mac Ayres and Starfall (Rescheduled from 11/1/2024) (POSTPONED) Tickets Thu, Nov 1, 2029 8:00 pm at Pechanga Arena - San Diego in San Diego, CA
WPoS's Content - Page 34
Funky Town Gore Cartel Video
Rugged Gentleman Barber Shop Martinsburg Wv
FREE Houses! All You Have to Do Is Move Them. - CIRCA Old Houses
Fox And Friends Mega Morning Deals July 2022
Gideon Nicole Riddley Read Online Free
Appleton Post Crescent Today's Obituaries
Polk County Released Inmates
Jasgotgass2
Author's Purpose And Viewpoint In The Dark Game Part 3
Atom Tickets – Buy Movie Tickets, Invite Friends, Skip Lines
Bunkr Public Albums
SF bay area cars & trucks "chevrolet 50" - craigslist
Kutty Movie Net
R: Getting Help with R
Arcanis Secret Santa
Dancing Bear - House Party! ID ? Brunette in hardcore action
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Theater X Orange Heights Florida
Rubmaps H
M Life Insider
Bumgarner Funeral Home Troy Nc Obituaries
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 5810

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.