SMS MFA Configuration

JumpCloud provides SMS based Multi-Factor Authentication (MFA) using Twilio Verify via a Bring Your Own Telephony (BYOT) architecture. This configuration allows administrators to deliver One-Time Passwords (OTPs) to users via standard SMS channels.

Since SMS transmission is susceptible to vector attacks like carrier interception and SIM duplication, it’s a less secure protocol than token based or push-notification factors. As a best practice, configure SMS MFA only as a secondary or backup recovery method for your organization.

To protect your organization from brute force attempts and automated OTP flooding, JumpCloud and Twilio evaluate incorrect OTP submissions in real time.

Warning:

According to NIST guidelines, SMS authentication has security trade-offs, making it vulnerable to intercept attacks such as SIM Swapping. Admins must acknowledge these risks and proceed based on specific business continuity needs.

For Admins

Enabling SMS MFA

Prerequisites:

To connect JumpCloud to your Twilio Verify instance for SMS OTP based MFA:

  1. Log in to the JumpCloud Admin Portal.

Important:

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Click Security > MFA Configurations.
  2. Scroll down to SMS One-Time Passcode (OTP). Click the toggle button to enable it.
    A screenshot showing MFA settings in Jumpcloud enterprise portal
    A dialog box opens displaying a warning. Select the checkbox to acknowledge and click Proceed.
    A screenshot showing Enable SMS OTP MFA popup.
  3. Enter the following details.
    A screenshot showing SMS MFA settings
    • Account SID: Your unique Twilio identifier (Starts with AC followed by a 32-character alphanumeric string).
    • Service SID: Your specific Twilio Verify Service identifier (Starts with VA followed by a 32-character alphanumeric string).
    • Auth Token: Your confidential Twilio account token (A 32-character alphanumeric string).
  4. Upon saving, JumpCloud automatically validates the credentials against Twilio:
    • Validation Success: SMS MFA is instantly enabled and functional for your organization.
    • Validation Failure: The system prompts you with an error message to re-enter the correct credentials before the factor can be activated.

For Users

User Enrollment

JumpCloud recommends configuring TOTP (Time-Based One-Time Password) or WebAuthn as the primary authentication factor, with SMS reserved as a backup factor.

If administrative policies mandate both a primary and a backup factor, the system enforces enrollment during the user's active login session using one of two workflows:

  • Self Enrollment: Users configure their required factors on the JumpCloud user portal.
  • Guided Enrollment Workflow: The system automatically prompts users to configure both factors in a sequential, step-by-step wizard before granting resource access.

The Enrollment Process:

  1. Log in to the JumpCloud user portal.
  2. Go to Security> Multi-Factor Authentication.
  3. Next, open the SMS OTP dropdown, and click the Set Up button.
    A screenshot showing the SMS MFA option under Security in JumpCloud user portal.

Note:

For first time users, a dialog appears prompting them to select their country code and their mobile number.

  1. Select the country code and enter your mobile number. Click Send verification code.
    A screenshot showing the "Enroll SMS OTP as Backup MFA" dialog in JumpCloud user portal.
  2. JumpCloud instantly requests Twilio Verify to send an OTP via SMS to the provided number.
  3. Enter the received code in the dialog box.
    A screenshot showing the OTP verification screen.
  4. Click Verify and finish.
    JumpCloud verifies the code with Twilio. Upon successful validation, the mobile number is enrolled for SMS MFA and ready to receive the OTP.

Resource Access Scenarios

Users may experience various workflows depending on how the Conditional Access Policies are structured for your organizations.

Note:

SMS MFA is available as a factor only for User Portal and SSO Applications. It’s recommended to use Primary MFA factors for better security, but enable SMS exclusively based on business specific requirements via specific MFA factor selection through JumpCloud Conditional Access Policies.


Re-Enrolling Users 

If a user changes their phone number, they must update their MFA profile to maintain access.

  1. Log in to the JumpCloud user portal (with any available MFA factor if enrolled and enforced).
  2. Go to Security > Multi-Factor Authentication. Delete the active SMS MFA factor enrollment.
  3. Click  Set up to initiate a fresh re-enrollment flow.
    Register the new mobile number using the standard verification process to continue access.

Note:

JumpCloud enforces a strict one-to-one relationship; a user profile can have only one active mobile number bound to it for SMS MFA at a given time.

Policy Requirement User Experience Flow
CAP Enforced for the resource with "Any Factors" During a fresh browser session, primary enrolled factors are displayed first. If unavailable, the user can click "Choose a different way" to select and complete SMS OTP based MFA.
Enforced with SMS as the only "Specific Factor" for SSO Apps (User Not Enrolled) The user enters a gated session that mandates the immediate enrollment of their phone number for SMS MFA. Once enrolled, they provide the SMS OTP and gain resource access.
Enforced with SMS as the only "Specific Factor" for SSO Apps (User Already Enrolled) The user is immediately prompted for an OTP code via SMS. Upon successful validation, users log in to the target resource.

Troubleshooting: Delayed Delivery

JumpCloud features built-in timers to balance a smooth user experience with strict security controls in case of delayed SMS delivery to users from telecom providers.

Handling Delayed SMS Delivery

If a one-time passcode (OTP) is not received immediately, the system manages requests through a structured countdown workflow:

  1. A security timer keeps ticking to look for user input of the OTP code received through SMS.  If this timer expires without any user input, the session closes, and the user is redirected to next steps.
  2. After a minute of no code entered, users get a "Resend SMS" option. Users can click this to retry and get an SMS code delivery from the provider. For security reasons, users get only 1 attempt for retrying SMS delivery.
    A screenshot showing "Set-up Multi-factor Authentication" dialog

For security purposes, users entering an incorrect passcode multiple times during SMS multi-factor authentication (MFA) setup will result in an error during registration. If this happens, Users will need to restart the MFA enrollment process from the beginning or contact administrators for further assistance.
A screenshot showing MFA Set up screen in JumpCloud user portal.

Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case