Add Phone as a second factor

FusionAuth Reactor logo

This feature is only available in paid plans. Please visit our pricing page to learn more.

Available since version 1.26.0

Phone two factor is not enabled by default. Configure your tenant by navigating to Tenants -> Edit Tenant -> Multi-Factor .

Enable MFA method on Tenant (Admin Facing)#

Configure Tenant SMS

Configure Tenant SMS

You can enable the phone factor on the tenant level by following these steps:

  • Set SMS and/or Voice to enabled
  • For each enabled message type, select a messenger (previously created, see documentation)
  • For each enabled message type, select a template (FusionAuth ships with a default to be customized if needed)

Enable Phone Factor from Account Management (User Facing)#

Account Management Index

Account Management Index

  1. Navigate back to your account page.
  2. Click Manage two-factor
  3. Click Add two-factor
  4. There will be an option for Phone.

Add Factors

Add Factors Add SMS Authenticator Add SMS Authenticator

Next,

  1. Enter your phone number.
  2. If SMS and Voice are both enabled, select which type of message to send.
  3. Click on Send a one-time-code.
  4. Enter the Verification Code
  5. Click Enable.

Recovery Codes (User Facing)#

Now you will be presented with recovery codes. Save these in a safe space.

Recovery Codes

Recovery Codes

Success!

Upon the next login, you will be prompted for a code sent by phone in addition to your password. If the tenant has both SMS and Voice message types enabled you will be asked to choose which type to receive, otherwise the message will be sent automatically.

See It in Action (User Facing)#

With phone MFA enabled, if you log out and log back in you will be presented with the following screen in addition to the typical login screen.

Challenge Account Management

Challenge Account Management