Verify a user’s identity with extra security
If we suspect that an unauthorized person is trying to access one of your user’s accounts, we present them with an extra security question or challenge. For example, we might send a verification code to the real user’s phone. If the person can’t answer the question or challenge, they can’t access the account.
Types of challenges
Google decides which challenge is appropriate to present to a user based on multiple security factors.
Mobile device challenges
- A prompt that asks the user to tap Yes and then tap a number on their phone.
- A text message or phone call with a verification code to the user's recovery device with instructions to access their account.
If your organization uses Google Mobile Management, we might ask users to use their managed mobile device to verify their identity (the device they normally use to access their corporate account). For more information about Google Mobile Management, see Manage your organization's mobile devices.
Employee ID login challenge
Recovery email challenge
Before you can use challenges
Before we can verify a user's identity with their recovery phone number or email account, the user needs to give us those details. When a user signs in, they see a message asking them to provide a recovery phone number or email account. The message appears periodically until the user provides their details. If you use the employee ID login challenge, you need to make sure that IDs are associated with your users' accounts. For details, see Add employee ID as a login challenge.
Extra questions and challengesWhen does a user see a question or challenge?
A user is presented with the login challenge when a suspicious login is detected, such as the user not following the sign-in patterns that they've shown in the past.
Important: Google decides which challenge is appropriate to present to a user based on multiple security and usability factors. For example, the employee ID login challenge might not always be presented to a specific user, even if you turned it on.
Yes. For details, see Set up a recovery phone number or email address.
2-Step Verification is a login challenge. So when your users have it on, they won't get another login challenge or the interstitial page shown above.
For the same reason, Admin Reports displays each 2-Step Verification as a login challenge.
Currently, challenges aren’t enabled for organizations with single sign-on (SSO). Users in organizations with SSO won't be asked to verify their recovery phone number or recovery email address.
Yes, all G Suite editions include extra security questions and challenges.
We determine whether a sign-in is suspicious when our risk-analysis system identifies an attempt that’s outside the normal pattern of user behavior. For example, a user might try to sign in from an unusual location or in a manner associated with abuse.
Phone verificationIf users in my organization don’t have a corporate phone, is there another way to verify their accounts?
Yes, there are different challenges. Depending on the information that’s available for a user’s account, users are presented with a different challenge, such as entering their employee ID or recovery email address. If a user doesn’t have access to their phone, they can use backup codes to sign in. For details, see Sign in using backup codes.
The user can update the recovery information through the account settings.
If the user doesn’t enter a recovery phone number, other challenges apply, such as entering their recovery email address or using their employee ID.
Disabling a challengeIf the user can't verify their identity, can I disable the login challenge?
In some situations, an authorized user can’t verify their identity. For example, they might not have a phone signal and can’t get the verification code. Or, they can’t remember or find their employee ID.
If this happens, as an administrator you can temporarily turn off the login challenge to allow them to sign in:
- Sign in to the Google Admin console.
- Find the user account.
- Click the row for the user account to display the user information page.
- Click Security.
- Click Login challenge.
- Click Turn Off For 10 Minutes.
It might take several minutes for this change to take effect on the user account. At that point, the login challenge is off for 10 minutes to allow the user to sign in.
You can also change the user's password to grant access to a session that is locked because the user can’t verify their identity.
No, you can’t turn off this feature for your entire organization. You can only turn it off temporarily on a per-user basis.
No, only an administrator can turn the login challenges off temporarily.
Administrator challengesHow can an administrator who can’t verify their identity re-enter their account?
As an administrator, you can bypass the challenge and regain access to your account by resetting your password. At the bottom of the Login Challenge screen, click the Click here to reset your password instead link.
If a super administrator user can't verify their identity, then another super administrator (if available) can temporarily turn off the login challenge for them, as described in the steps above.
Alternatively, the super administrator can bypass the login challenge by resetting their password. At the bottom of the Login Challenge screen, click the Click here to reset your password instead link.
Note: The automated password reset option isn't available to all super administrators. For more information about admin account recovery, see Add recovery options to your administrator account.