Aller au contenu principal

Verify or change your phone number

Phone verification confirms that you own and control the phone number stored on your account. This article explains how to add or change your number, what step-up MFA protects the change, and how to troubleshoot common SMS delivery issues.

Before you begin

  • You are signed in to VaultPAM.
  • You have at least one MFA method enrolled (TOTP authenticator app or hardware security key). If you have not enrolled one yet, see Set up MFA first — you cannot complete a phone change without it.

What is phone verification?

When you add or change your phone number, VaultPAM sends a one-time 6-digit code to that number via SMS. You enter the code to prove that you can receive messages on the number. Only after a successful code entry does the platform record the phone number as verified.

Phone verification is separate from your account password and from any other MFA method you have set up. It confirms phone ownership — it does not replace your password or your authenticator app.

Tip: A verified phone number is a prerequisite for future features such as SMS-based alerts and compliance reporting. Verifying your phone now ensures your account is ready.

Add or change your phone number

Phone-number management is on the Settings → Profile tab. The Security tab does not include a phone field.

  1. Click your avatar or username in the top-right corner and select Settings.
  2. Open the Profile tab.
  3. Locate the Phone number field. If you have no phone on file, the field is empty. If you already have a verified phone, the current number is shown.
  4. Type your new phone number in international format: +<country code><number>, for example +48123456789 for a Polish mobile number or +12025550173 for a US number. See What characters are allowed below.
  5. Click Request change.
  6. A step-up MFA challenge modal appears — see What is step-up MFA for what to expect. Complete the challenge.
  7. Once the challenge is accepted, VaultPAM immediately sends an SMS to the new phone number. A dialog or inline prompt asks you to enter the code.
  8. Enter the 6-digit code from the SMS. You have 3 attempts and the code is valid for 10 minutes.
  9. On success, your phone number is updated and shown as verified.

Important: Your original phone number remains active until you successfully complete step 8. If you start a change but do not finish it, your original number stays on file and the new one is never recorded.

What characters are allowed in the phone field?

The phone number field follows the international E.164 standard. The only characters permitted are:

  • Digits (0–9)
  • A single + sign at the very beginning of the number (the country-code prefix)

The field enforces this as you type: a letter, space, dash, or any other character simply does not appear in the field. You do not need to delete anything — the field silently ignores disallowed characters.

Examples of valid formats:

CountryExample
Poland+48123456789
United States+12025550173
Germany+491701234567
United Kingdom+447911123456

Common mistakes to avoid:

  • Spaces are filtered out automatically: +48 123 456 789 becomes +48123456789.
  • Dashes and parentheses are filtered out automatically: +1 (202) 555-0173 becomes +12025550173.
  • Do not omit the country code: 123456789 without a leading + is invalid.

Tip: Pasting a number in a formatted style (for example, from a contacts app) is fine — the field strips non-digit characters automatically and keeps only digits and the leading +.

What is step-up MFA and why is it required?

Step-up MFA is a short, one-time confirmation that you are the legitimate account owner at the moment you request a sensitive change. Unlike login MFA (which proves your identity once at the start of a session), step-up MFA is re-verified at the point of a high-risk action — in this case, changing your phone number.

A phone number is a significant piece of account data. If an attacker gained access to your browser session, they could attempt to replace your verified phone with one they control. Requiring a fresh MFA confirmation before dispatching the change ensures that even a hijacked session cannot execute a phone change without also controlling your authenticator device.

When you click Request change, a modal asks you to complete one of the following, depending on what MFA method you have enrolled:

  • TOTP code — open your authenticator app and enter the current 6-digit code shown for this account.
  • Hardware security key — insert your key and tap it when prompted.
  • Other enrolled method — follow the on-screen prompt.

Once the challenge is accepted, VaultPAM records a "freshness" timestamp for your session — you are not challenged a second time during the same action. The freshness window is 10 minutes by default (your organization may configure a shorter or longer window, typically 5–15 minutes).

If you have not enrolled any MFA method yet, you cannot complete a phone change until you do. See Set up MFA.

Troubleshooting

I don't receive the SMS code

  1. Wait 30 seconds. SMS delivery can be delayed depending on mobile network conditions. The Resend button is intentionally locked for 30 seconds after each send to prevent duplicate delivery.
  2. Check your phone signal and mobile data. Weak signal or no data connection can delay or block SMS delivery.
  3. Confirm the number is correct. On the phone-change screen, check that the number shown in the confirmation prompt matches the number you intended.
  4. Click Resend after the 30-second cooldown. You may resend up to 5 times in a rolling 60-minute window. Each resend invalidates the previous code immediately.
  5. If multiple resends fail, this is most likely an SMS delivery issue rather than your phone or account. Contact your VaultPAM admin with the approximate time you attempted the change — this is not a user error.

The code is wrong or expired

Wrong code: you have 3 attempts per code. After 3 failed attempts the code is invalidated and a Resend button appears (after the 30-second cooldown). Each resend gives you a fresh 3-attempt allowance.

Expired code: codes are valid for exactly 10 minutes. After that, click Resend to get a new code — you do not need to re-enter the phone number.

Rate limit reached: if you request more than 5 codes within 60 minutes, further requests are temporarily blocked until the oldest request in the window is more than 60 minutes old. If you believe this limit was reached in error, contact your VaultPAM admin.

How do I cancel a pending change?

If you started a phone-change request but decided not to complete it, discard it at any time without affecting your current verified phone:

  1. Pending-change banner — a banner at the top of the Profile tab reads "Phone change pending verification." Click Discard phone change in the banner.
  2. Verification modal — if the SMS code entry dialog is still open, click Cancel or Discard.

Discarding immediately removes the pending phone number, invalidates any issued SMS code, keeps your original verified phone active, and records an audit event that the change was abandoned. You can start a new phone-change request immediately after discarding.

What does the "Phone change pending verification" banner mean?

This banner appears on the Profile tab when you have started a phone-change request but have not yet entered the SMS verification code. It means:

  • You (or someone using your session) requested a change to a new phone number.
  • The new number does not become active until the 6-digit SMS code is entered successfully.
  • Your original phone number is still active.
  • The banner disappears when you either verify the new number or discard the pending change.

Important: If you see this banner and did not request a phone change, your account session may have been compromised. Click Discard phone change immediately, then change your password and review your active sessions in Settings → Security. Contact your VaultPAM admin if the banner reappears.

My organization is missing — what is an "orgless" user?

Under normal circumstances every active user belongs to at least one organization. An "orgless" state can occur when your invitation has not yet been processed, your membership was revoked and you have not been re-invited, or you are a user who has not yet been assigned to any organization.

Phone-change requests still require a step-up MFA challenge either way. The step-up freshness window is normally set by your organization's security policy; if you have no organization, VaultPAM falls back to a default window of 10 minutes (configurable by your admin within a 5–15 minute range). If you believe you should belong to an organization but are showing as orgless, contact your VaultPAM admin.

Privacy: how is my phone number stored and used?

  • Storage: your phone number is stored encrypted.
  • Transmission: the plaintext phone number is sent only to the configured SMS delivery provider to send the verification code. It is not shared with any other third party.
  • Audit logs: VaultPAM emits audit log entries for phone verification events (code sent, verified, failed, phone changed). Audit entries contain a redacted cryptographic digest (HMAC-SHA-256) of your phone number, not the number itself — admins can correlate audit events without recovering the actual number.
  • Deletion: if your account is deleted, or you exercise a right to erasure under applicable data protection law, your phone number and any pending verification tokens are purged. Audit log entries are retained (as required for compliance) but contain only the digest.

Phone verification at registration

Standard registration: providing a phone number is optional. If you provide one, you are offered a chance to verify it right after the registration form; you can verify immediately or skip and verify later from Settings → Profile. If you skip, your account is created with the phone stored but unverified.

Organization founder registration: if you are registering as the founder of a new organization, phone number entry and verification is mandatory — the organization cannot be created until the SMS code is verified. The flow is the same as standard verification (enter your number, receive the SMS, enter the code) but there is no option to skip. If you cannot receive SMS, contact your VaultPAM admin to discuss alternative onboarding options.