Vonage Business Cloud AU Support

Vonage Business Communications Support

Enter a search topic

Vonage Support
Expand All | Collapse All

Two-Factor Authentication (2FA)

Updated: 9/4/2026 3:16 AM

Two-factor authentication (2FA) is an added security layer for your VBC account. It can be enforced at the account level for all users, or individual users can enable it for themselves. 

  • When enabled, a password and a six-digit verification code are required to sign in. The code is obtained from the phone number supplied by each user. A Super User or Administrator cannot set this phone number for their users. 
  • A mobile phone number is required for verification. We accept US mobile numbers and international mobile numbers for these Supported Countries. A Virtual or Vonage phone number is not acceptable for use.

While 2FA is always active, you may not be prompted for a verification code at each sign-in. This feature is intentional, as all sign-in activity remains monitored and protected in real time. For more details, see our FAQs


IMPORTANT: Customers who want to turn on International Dialing must must enforce a Multifactor Authentication (MFA) solution, such as 2FA account-wide. 


Supported Countries
ArgentinaEgyptLithuaniaSerbia
AustraliaEstoniaLuxembourgSingapore
AustriaFinlandMalaysiaSlovakia
BangladeshFranceMexicoSlovenia
BelgiumGermanyMoldovaSouth Africa
BrazilGreeceNetherlandsSouth Korea
BulgariaHondurasNew ZealandSpain
CanadaHong KongNorwaySri Lanka
ChileHungaryPakistanSweden
ChinaIndiaPanamaSwitzerland
ColombiaIndonesiaPeruTaiwan
Costa RicaIrelandPhilippinesThailand
CroatiaIsraelPolandTurkey
CyprusItalyPortugalUkraine
Czech RepublicJapanPuerto RicoUnited Arab Emirates
DenmarkLatviaRomaniaUnited Kingdom
Dominican RepublicLebanonSaudi ArabiaUnited States
Enforce 2FA at the Account Level

Two-factor authentication (2FA) can be enforced account-wide at any time to ensure the overall security and protection of your services. To use International Dialing, you must enforce MFA. This solution is also an option for our Multifactor Authentication (MFA) Policy, which we are rolling out in phases.

If Enforce MFA PolicyFollow the instructions in your notification and review Enforce Multifactor Authentication for more details. 

If International Dialing /
Overall Account Security

Contact Us to enforce 2FA account-wide. 
To View 2FA Status
  1. Sign in to the Admin Portal
  2. Click Account, then click Security Settings.
Set 2FA at the User Level

You can set 2FA at the user level before it is enforced account-wide:

  • If you set it before 2FA is enforced, your verification phone number remains in effect once applied account-wide.
  • If you set it after 2FA is enforced, you are prompted to enter a verification phone number for future sign-ins once it is applied account-wide. 

To set your verification phone number:

Desktop App 
(All User Types)
  1. Sign in to the Desktop App.
  2. Click your Avatar/Initials (top left), then click Settings, then click Security.
  3. Click Set Up Number.
  4. Type your mobile device’s phone number, then click Send Code.
  5. Enter the 6-digit code (valid for 10 minutes) sent to your mobile device through text message.

    NOTE: The 6-digit code option allows you to resend after 2 minutes if the code is not received.
  6. Click Submit
Mobile App 
(All User Types)
  1. Tap the Avatar/Initials (Upper left) to open the Home menu.
  2. Tap Settings, then tap Two Factor Authentication.
  3. Tap Set Up Number.
  4. Enter your mobile device’s phone number, then select Send Code.
  5. Enter the 6-digit code (valid for 10 minutes) sent to your mobile device by text message.

    NOTE: The 6-digit code option allows you to resend after 2 minutes if the code is not received.
  6. Tap Submit.
Admin Portal
(Super User,
Account Administrators, and
User Administrators)
  1. Sign in to the Admin Portal.
  2. Click Phone System and then click Users.
  3. Hover over your username, then click the Pencil icon.
  4. Click Security, scroll down to Two-Factor Authentication, then click on Set up Number.
  5. Type your mobile device’s phone number, then click Send Code.
  6. Enter the 6-digit code (valid for 10 minutes) sent to your mobile device by text message.

    NOTE: The 6-digit code option allows you to resend after 2 minutes if the code is not received.
  7. Click Submit.
Update/Change 2FA Phone Number

Only an Account Super User (ASU) with 2FA or SSO enabled on their profile can force a reset for any account user, except their own. If you are an ASU, you must Contact Us to reset. All resets require authorization from the actual user. 

Reset a phone number for a user as follows:

  1. Receive authorization from the actual user. 
  2. Sign in to the Admin Portal (as ASU). 
  3. Click Phone System, then click Users.
  4. Select the user you want to reset, then click Security.
  5. Scroll to Two-Factor Authentication, then click Remove Number.

    Once the number is removed, the user is prompted to enter a new phone number on their next sign-in.  

    BEST PRACTICE: Always perform a password reset if the user suggests their 2FA has been compromised. 
FAQs

Can I remove or disable 2FA?
Our Multifactor Authentication (MFA) Policy requires account-wide enforcement of two or more verification factors to safeguard systems against unauthorized access.  Whether you use 2FA or another method such as Passkeys, MFA cannot be removed or disabled. 

I was not prompted for a verification code when I signed in. Why?
We use continuous, intelligent, real-time security monitoring to evaluate ALL sign-in attempts, and you are always protected from unauthorized sign-in attempts.

  • If a sign-in is low risk (e.g., signing in from a recognized device and location), the verification code may be bypassed. This feature is intentional.
  • If a sign-in detects any risk indicator (e.g., an unrecognized device, unusual location, or other alert factors), a prompt will appear for your verification code.

How often am I required to authenticate with an MFA solution such as 2FA? Is it every 24 hours? 
The frequency of prompts is determined by our security system’s assessment of your sign-in attempt. The system evaluates risk indicators to determine when re-verification is necessary.

Can I update/change the phone number I use for 2FA?
Contact your Account Super User (ASU) for assistance. If you are an ASU, you must contact us to reset it. All reset requests require authorization from the actual user. 

Can I set up 2FA with an email address instead of a phone number?
No. Email addresses are more vulnerable to interception and cyberattacks compared to other verification methods. A mobile phone number is required.

I have a user who has left the company. Can I reset 2FA to retrieve their data, such as text messages, business contacts, and so on?
To gain access to a departed user, the ASU must reset both the Password and 2FA for that user.  

Do VBC API users adhere to an MFA Policy such as 2FA? 
No. This policy does not impact VBC API users.

When 2FA is enabled account-wide, why am I signed out of all active sessions? 
When an MFA Policy is enforced account-wide, all users who are not signed in with Single Sign-On (SSO) or 2FA (or other MFA) at the user level are signed out of all active sessions. On their next sign-in attempt, non-MFA users will be prompted to set up their verification method.

If our account uses Single-Sign-On (SSO), why must we enforce your Multifactor Authentication (MFA) policy?
SSO always overrides our MFA Policy; however, if any user is disabled for SSO, they automatically default to the MFA policy. In this instance, if disabled for SSO and 2FA is enforced account-wide, they will be prompted to enter a phone number for their verification code on their next sign-in attempt.

Is there a way to determine which users have 2FA enabled at the user level before it is enforced account-wide?
No, but these users will not be affected when it is enabled. Instead, only users without Single Sign-On (SSO) or 2FA enabled at the user level are impacted. On their next sign-in attempt, these users will be prompted to set up their verification method.

Can I use an international phone number for 2FA?
Yes. See Supported Countries for the current list.

What is your data retention/compliance policy for phone numbers used for 2FA?
The phone numbers used for 2FA are stored in our system; however, they are not exposed to anyone after setup. These phone numbers are not used for any other purpose.

Did this article answer your question?