SourCherry Help Centre
Home â€ș Phone System â€ș Phone numbers

Mandatory 2FA for Phone Number Updates

SourCherry now requires two‑factor authentication (2FA) whenever a user’s phone number is changed. This aligns phone updates with the existing email change + 2FA flow, closes a high‑risk account‑takeover path, and improves overall security. This article explains how it works, who it affects, and how to complete verification using Email, SMS (to an existing verified number), or an Authenticator App (TOTP).


TABLE OF CONTENTS


What is 2FA for Phone Number Updates?


Mandatory 2FA adds a verification challenge any time a user attempts to change the phone number on their SourCherry profile. The verification must be completed using a previously verified channel—your existing email, your existing verified phone number, or a TOTP authenticator app if you’ve enabled it. This prevents attackers from swapping your number and taking over your account.


SourCherry enforces a 2FA check before saving any phone number change. OTPs/codes are delivered only to trusted, verified channels, never to the new phone number being added.


Key Benefits of 2FA for Phone Number Updates


Understanding the benefits helps teams adopt best practices and explain the change to users. The bullets below focus on day‑to‑day impact for admins and end users.



Eligibility & Prerequisites


Verifying at least one secure channel beforehand ensures you can pass 2FA when updating your phone number. Use this checklist before attempting a change.



Tip: If you currently have no verified channel, set up TOTP or verify your email first so you don’t get blocked during the phone update.


Supported Verification Channels & Selection Logic


SourCherry only offers verification options that are already trusted for your account. This section clarifies which options you’ll see and why.



What you’ll see in-product: A channel selection modal listing eligible options only.


Rate Limiting Rules


Rate limiting protects accounts from abuse. Knowing the limits helps users plan updates and troubleshoot lockouts.



Note: If you encounter a limit unexpectedly, confirm whether another admin or automated process attempted changes on your behalf the same day.


Admin vs. User Update Paths


The experience is similar for everyone, but admins may initiate changes on behalf of team members. Understanding who receives the OTP and where to start avoids confusion.



Security & Audit Considerations


These safeguards help organizations maintain a secure, trackable profile change process and quickly identify suspicious behavior.



How To Set Up and Use the Mandatory 2FA for Phone Number Updates


Follow the steps below to update a phone number securely. Steps include both the self‑service flow and the admin flow, where applicable.


A) Update your own phone number (self‑service)


  1. Go to Settings → My Profile (or your user profile page).



  2. In Personal Data, edit the phone number.



  3. Enter the new phone number, then click Update Profile.



  4. When the Choose how to verify modal opens, select one of your available channels:

    • Email (OTP sent to your verified email)

    • Text message (OTP sent to your existing verified phone)

    • Use Authenticator App (enter the 6‑digit TOTP)



  5. Click Continue. If you selected Email or SMS, retrieve the OTP and enter it to verify.



  6. After successful verification, confirm the change. You’ll see a success message, and your profile will reflect the new number.


Important: If you don’t see SMS as an option, your current phone is not verified. Use Email or Authenticator App instead, or verify your phone first.



B) Update a team member’s phone number (admin)


  1. Go to Settings → Team and open the team member’s profile.



  2. Edit the Phone number and enter the new number.



  3. On Choose how to verify, select an available channel. The code is delivered to the team member’s verified email/phone, or they can provide the code from their Authenticator App.



  4. Enter the OTP (or have the team member provide it securely) and click Continue to complete the change.


Security reminder: OTPs will not be sent to the new number you’re adding.


Troubleshooting


If you encounter errors or cannot complete verification, use these targeted tips to resolve common issues quickly.



Frequently Asked Questions


Q. Why can’t I send the OTP to my new phone number?
For security, OTPs only go to channels already verified on your account. This blocks attackers from adding a new number and receiving the OTP there.



Q. I don’t see SMS as a verification option—what should I do?
SMS appears only if your existing phone is verified. Use Email or Authenticator App (TOTP) instead, or verify your current phone first.



Q. How many times can I attempt a change per day?
You can attempt up to 5 phone/email changes per user per day. After that, you’ll be temporarily blocked until the counter resets.



Q. Who receives the OTP when an admin updates a user’s phone?
The user being edited. OTPs are sent to that user’s verified channels, not to the admin.



Q. Can I use my authenticator app instead of Email/SMS?
Yes, if you’ve enabled TOTP for your account, you can select Use Authenticator App during verification and enter your current 6‑digit code.



Q. What if I’ve lost access to both my email and phone?
Use backup codes (if available) or contact your account owner/admin for identity verification and recovery support.



Q7. Does this change anything about updating my email address?
Email updates already require 2FA. Phone updates now follow the same security standard for consistency and safety.