Two-factor authentication (2FA) is an added security layer for your VBC account. It can be enforced at the account level for all users, or individual users can enable it for themselves.
While 2FA is always active, you may not be prompted for a verification code at each sign-in. This feature is intentional, as all sign-in activity remains monitored and protected in real time. For more details, see our FAQs.
IMPORTANT: Customers who want to turn on International Dialing must must enforce a Multifactor Authentication (MFA) solution, such as 2FA account-wide.
| Argentina | Egypt | Lithuania | Serbia |
| Australia | Estonia | Luxembourg | Singapore |
| Austria | Finland | Malaysia | Slovakia |
| Bangladesh | France | Mexico | Slovenia |
| Belgium | Germany | Moldova | South Africa |
| Brazil | Greece | Netherlands | South Korea |
| Bulgaria | Honduras | New Zealand | Spain |
| Canada | Hong Kong | Norway | Sri Lanka |
| Chile | Hungary | Pakistan | Sweden |
| China | India | Panama | Switzerland |
| Colombia | Indonesia | Peru | Taiwan |
| Costa Rica | Ireland | Philippines | Thailand |
| Croatia | Israel | Poland | Turkey |
| Cyprus | Italy | Portugal | Ukraine |
| Czech Republic | Japan | Puerto Rico | United Arab Emirates |
| Denmark | Latvia | Romania | United Kingdom |
| Dominican Republic | Lebanon | Saudi Arabia | United States |
Two-factor authentication (2FA) can be enforced account-wide at any time to ensure the overall security and protection of your services. To use International Dialing, you must enforce MFA. This solution is also an option for our Multifactor Authentication (MFA) Policy, which we are rolling out in phases.
| If Enforce MFA Policy | Follow the instructions in your notification and review Enforce Multifactor Authentication for more details. |
|
If International Dialing / | Contact Us to enforce 2FA account-wide. |
| To View 2FA Status |
|
You can set 2FA at the user level before it is enforced account-wide:
To set your verification phone number:
| Desktop App (All User Types) |
|
| Mobile App (All User Types) |
|
| Admin Portal (Super User, Account Administrators, and User Administrators) |
|
Only an Account Super User (ASU) with 2FA or SSO enabled on their profile can force a reset for any account user, except their own. If you are an ASU, you must Contact Us to reset. All resets require authorization from the actual user.
Reset a phone number for a user as follows:
Can I remove or disable 2FA?
Our Multifactor Authentication (MFA) Policy requires account-wide enforcement of two or more verification factors to safeguard systems against unauthorized access. Whether you use 2FA or another method such as Passkeys, MFA cannot be removed or disabled.
I was not prompted for a verification code when I signed in. Why?
We use continuous, intelligent, real-time security monitoring to evaluate ALL sign-in attempts, and you are always protected from unauthorized sign-in attempts.
How often am I required to authenticate with an MFA solution such as 2FA? Is it every 24 hours?
The frequency of prompts is determined by our security system’s assessment of your sign-in attempt. The system evaluates risk indicators to determine when re-verification is necessary.
Can I update/change the phone number I use for 2FA?
Contact your Account Super User (ASU) for assistance. If you are an ASU, you must contact us to reset it. All reset requests require authorization from the actual user.
Can I set up 2FA with an email address instead of a phone number?
No. Email addresses are more vulnerable to interception and cyberattacks compared to other verification methods. A mobile phone number is required.
I have a user who has left the company. Can I reset 2FA to retrieve their data, such as text messages, business contacts, and so on?
To gain access to a departed user, the ASU must reset both the Password and 2FA for that user.
Do VBC API users adhere to an MFA Policy such as 2FA?
No. This policy does not impact VBC API users.
When 2FA is enabled account-wide, why am I signed out of all active sessions?
When an MFA Policy is enforced account-wide, all users who are not signed in with Single Sign-On (SSO) or 2FA (or other MFA) at the user level are signed out of all active sessions. On their next sign-in attempt, non-MFA users will be prompted to set up their verification method.
If our account uses Single-Sign-On (SSO), why must we enforce your Multifactor Authentication (MFA) policy?
SSO always overrides our MFA Policy; however, if any user is disabled for SSO, they automatically default to the MFA policy. In this instance, if disabled for SSO and 2FA is enforced account-wide, they will be prompted to enter a phone number for their verification code on their next sign-in attempt.
Is there a way to determine which users have 2FA enabled at the user level before it is enforced account-wide?
No, but these users will not be affected when it is enabled. Instead, only users without Single Sign-On (SSO) or 2FA enabled at the user level are impacted. On their next sign-in attempt, these users will be prompted to set up their verification method.
Can I use an international phone number for 2FA?
Yes. See Supported Countries for the current list.
What is your data retention/compliance policy for phone numbers used for 2FA?
The phone numbers used for 2FA are stored in our system; however, they are not exposed to anyone after setup. These phone numbers are not used for any other purpose.