You are here:
SMS Identity Verification
Understand how and when users can verify their identity with one-time passcodes sent via text messages (SMS).

Use more general search terms.
Select fewer filters to broaden your search.
Understand how and when users can verify their identity with one-time passcodes sent via text messages (SMS).
| Available in: all editions |
By default, SMS one-time passcodes are available to Salesforce users as a verification method for device activation only. SMS one-time passcodes aren’t allowed as a verification method for internal users when multi-factor authentication (MFA) is enabled. However, external users who only access your Experience Cloud sites can use SMS one-time passcodes to log in with MFA. Learn how to configure this option. For information about the contractual requirement to use MFA when accessing Salesforce products, see the Salesforce Multi-Factor Authentication FAQ .
When a user requests an SMS one-time passcode, Salesforce sends a six-digit passcode to their verified mobile number. To finish verifying their identity, the user must enter the passcode in Salesforce within 15 minutes of receiving it.
If a user misses the 15-minute window to enter the passcode, they can request a different one. To limit the abuse of SMS functionality, users can’t request a passcode more than five times within the span of one hour.

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.