Mandatory Two-Factor Authentication for Phone Number Updates

About Mandatory 2FA for Phone Number Updates

To enhance the security of your account, the CRM now requires you to complete a two-factor authentication (2FA) step any time you change the phone number associated with your user profile. This verification ensures that only authorized users can make this sensitive change, protecting your account from unauthorized access.

Benefits of This Security Feature

  • Improved Account Security: Prevents account takeover by requiring verification through a trusted, pre-existing channel before a new phone number is saved.
  • Consistent User Experience: Provides a security process for phone number changes that is similar to the existing flow for updating an email address.
  • Reduced Abuse: Built-in daily limits on change attempts help protect against automated or malicious activity.

Before You Begin: Prerequisites

To successfully update your phone number, you must have at least one of the following verification methods already set up and accessible on your account:

  • A verified email address.
  • A phone number that is already verified.
  • An authenticator app (TOTP) enabled for your account.

You must also have the necessary permissions to edit your own profile, or, if you are an administrator, the permissions to edit team member profiles.

Available Verification Methods

When you attempt to change your phone number, you will be prompted to verify your identity using one of your existing, trusted channels. The available options will be:

  • Email: A one-time passcode (OTP) will be sent to your currently verified email address. This option is always available if your email is verified.
  • SMS: A one-time passcode will be sent via text message to your currently verified phone number. This option is only available if the phone number already on file is verified.
  • Authenticator App: You can enter a 6-digit code from your configured TOTP authenticator app. This option is available if you have previously set up an authenticator app.

Important: For security reasons, a code will never be sent to the new phone number you are trying to add.

How to Update Your Own Phone Number

  1. Navigate to Settings and then My Profile.
  2. In the Personal Data section, locate and edit the phone number field.
  3. Enter your new phone number and click Update Profile.
  4. A modal window titled Choose how to verify will appear. Select your preferred verification method from the available options (Email, SMS, or Authenticator App).
  5. Click Continue.
  6. If you selected Email or SMS, retrieve the one-time passcode and enter it in the provided field. If you selected the Authenticator App, enter the current 6-digit code.
  7. After successful verification, you will see a confirmation message, and your profile will be updated with the new number.

How to Update a Team Member's Phone Number (Admin)

  1. Go to Settings and then Team.
  2. Open the profile of the team member whose phone number you wish to update.
  3. Edit the phone number field and enter the new number.
  4. When the Choose how to verify modal appears, select one of the team member's available verification channels.
  5. The verification code will be sent to the team member's trusted channel (their email or existing phone number), not to you as the admin.
  6. The team member must complete the verification step to finalize the phone number change.

Rate Limits and Troubleshooting

To prevent abuse, a maximum of 5 phone number change attempts are allowed per user per day. If you reach this limit, you will see a message instructing you to try again later.

If you do not see the SMS option as a verification method, it means your current phone number on file is not verified. In this case, use your verified email or authenticator app to complete the update, or verify your current phone number first.