---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Minimize one-time out of band verifier lifetime duration \[Updated in Security Center 1.3\]

# Minimize one-time out of band verifier lifetime duration \[Updated in Security Center
1.3\] {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Manage the time duration for out-of-band verifiers.
An out-of-band verifier is an alternative delivery method for one-time code situations. For example, resetting a multi-factor token. If this method is enabled by administrators in the [Multi-factor authentication](https://www.servicenow.com/docs/x9F4d3vypyFMlkRmmKc~xw "Learn how to activate, use, and configure Multi-factor authentication (MFA).") plugin, a one-time code is delivered by email. Set one-time out-of-band verifiers to expire after 10 minutes to limit the validity window. A larger time window allows more time for the code to be compromised
through illicit means such as phishing, social engineering, or shoulder-surfing attacks.

## More information {#sc-short-one-time-out-of-band-verifier-lifetime__section_qhx_1b1_xwb}

{#sc-short-one-time-out-of-band-verifier-lifetime__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.multifactor.onetime.code.validity |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | integer |
| Recommended value | 10 |
| Default value | 10 |
| Category | [Authentication](https://www.servicenow.com/docs/b9CEYnMpryNiLMZU_fh~Tw "The authentication category covers the main elements of modern authentication to confirm an entity and its claims are authentic and correct, resistant to impersonation and prevent interception of passwords.") |
| Security risk | * Severity score: 3.9 * CVSS score: Low * Security risk details: Set one-time out-of-band verifiers to expire after 10 minutes. Anything longer increases the risk of the code being compromised by a bad actor. {#sc-short-one-time-out-of-band-verifier-lifetime__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | [Multi-factor authentication](https://www.servicenow.com/docs/x9F4d3vypyFMlkRmmKc~xw "Learn how to activate, use, and configure Multi-factor authentication (MFA).") |
| References | [Multi-factor Authentication criteria](https://www.servicenow.com/docs/UaxCFOriZDr2Dqz2xrK6fw "Use MFA criteria to determine which users and roles must use two-step verification.") |
[ ]

{#sc-short-one-time-out-of-band-verifier-lifetime__table_ajc_b43_3kb}

