Email One-Time Code Authentication (MFA) for External Applicants
External career site applicants now verify their identity with a secure 6-digit code sent to their registered email during both registration and login. This replaces the previous email link-based verification, removing dependency on mobile devices or third-party authentication apps. The flow includes real-time validation, clear messaging, and timing controls for a more reliable experience.
What's New
- Require a 6-digit email verification code during external applicant registration and login.
- Eliminate dependency on mobile devices and third-party authentication apps.
- Enforce a 10-minute code validity window with a 2-minute resend timer.
- Provide real-time validation, copy-paste support, and clear error and expiry messaging.
- Deliver standardized, system-managed verification emails via secure infrastructure.
- Apply MFA to both new account creation and existing profile login on external career sites.
Details
Description
Email One-Time Code Authentication, also referred to as multi-factor authentication (MFA), introduces a secure verification step for external applicants on Cornerstone career sites. When a candidate logs in or creates an account, the system sends a 6-digit code to their registered email address, which they enter on the verification screen to continue.
The verification code remains valid for 10 minutes, while a separate 2-minute timer controls when a new code can be requested. The verification field accepts numeric input only, supports copy-paste, and enables the submit button only once a valid code is entered. Candidates receive clear error messages for incorrect or expired codes, and standardized verification emails are delivered through Cornerstone's secure email infrastructure.
Business Need
Previously, external applicants relied on email link-based verification, which sometimes suffered from link delivery delays, email reliability issues, and unclear verification behavior. This created friction during registration and login on external career sites.
Because candidates often use personal email accounts and may lack access to authentication apps or company-managed devices, traditional MFA methods were impractical. Email-based one-time codes strengthen account security while removing the dependency on additional devices or third-party applications, improving both usability and protection.
Key Features
- Applicants must enter a 6-digit email verification code during both registration and login on external career sites, and cannot bypass the MFA screen.
- The enhancement eliminates dependency on mobile devices and third-party authentication apps, making secure access available to all external users.
- Each code remains valid for 10 minutes, while a 2-minute timer disables the resend option to prevent repeated requests; an in-window resend reissues the same code.
- The verification screen provides real-time validation, accepts numeric input with copy-paste support, and displays clear messaging for incorrect codes, expired codes, and temporary unavailability.
- Verification emails are standardized and system-managed, delivered through secure infrastructure with no customer-customizable templates or sender configuration.
- MFA applies to both candidates creating new accounts and applicants logging in with existing profiles.
Deployment & Considerations
This feature requires system-level initialization, so customers should first contact GCS to enable it. Once enabled, administrators can activate it through the feature activation preferences for their external career sites.
No additional email setup is required after activation. Note that verification email templates and sender configurations are not customer-customizable in this release, as emails are standardized and system-managed. The functionality applies specifically to external career sites.