Configure When Users Are Prompted to Verify Identity
- In Setup, enter Identity in the Quick Find box, and then clickIdentity Verification.
- Customize the identity verification settings, and then click Save.FieldDescriptionEnable the SMS method of identity confirmationAllows users to receive a one-time password deliveredvia SMS. If this setting is selected, administrators or users must verify theirmobile phone number before taking advantage of this feature. This setting isselected by default for all orgs.Require security tokens for API logins fromcallouts (API version 31.0 and earlier)In API version 31.0 and earlier,requires the use of security tokens for API logins from callouts. Examples areApex callouts or callouts using the AJAX proxy. In API version 32.0 and later,security tokens are required by default.Let users use a security key (U2F)Allows users to use a U2F security key fortwo-factor authentication and identity verification. Instead of using SalesforceAuthenticator, one-time passwords generated by an authenticator app, or one-timepasswords sent by email or SMS, users insert their registered U2F security keyinto a USB port to complete verification.Require identity verification duringtwo-factor authentication registrationRequires users to confirm theiridentities to add a two-factor authentication method, such as SalesforceAuthenticator, instead of requiring a relogin as before.Require identity verification for change ofemail addressRequires users to log in again and confirm their identity before the change to their email address is applied. Salesforce asks the user to verify identity using a registered verification method, such as Salesforce Authenticator, SMS text message, or email.Note If the user’s identity verification method is email, the verification code is sent to the user’s previously registered email address rather than the new email address.Allow location-based automatedverifications with Salesforce AuthenticatorAllow only from trusted IP addressesAllows users to verify identity byautomatically approving notifications in Salesforce Authenticator, whenever usersare in trusted locations such as a home or office. If you allow automatedverifications, you can allow them from any location or restrict them to onlytrusted IP addresses, such as your corporate network.
- Allow only from trusted IP addresses