Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Minimize one-time out of band verifier lifetime duration [Updated in Security Center 1.3]

Manage the time duration for out-of-band verifiers.

An out-of-band verifier is an alternative delivery method for one-time code situations. For example, resetting a multi-factor token. If this method is enabled by administrators in the Multi-factor authentication plugin, a one-time code is delivered by email. Set one-time out-of-band verifiers to expire after 10 minutes to limit the validity window. A larger time window allows more time for the code to be compromised through illicit means such as phishing, social engineering, or shoulder-surfing attacks.

More information

AttributeDescription
Configuration nameglide.multifactor.onetime.code.validity
Configuration typeSystem Properties \(/sys\_properties\_list.do\)
Data typeinteger
Recommended value10
Default value10
CategoryAuthentication
Security risk- Severity score: 3.9 - CVSS score: Low - Security risk details: Set one-time out-of-band verifiers to expire after 10 minutes. Anything longer increases the risk of the code being compromised by a bad actor.
Dependencies and prerequisitesMulti-factor authentication
ReferencesMulti-factor Authentication criteria

Parent Topic:Authentication