Managing external identities to enable secure access for partners, customers, and other non-employees
The expiration time for a one-time passcode depends on the scenario. When used as a first-factor authentication method, the passcode is valid for 30 minutes. However, when used for MFA as a second-factor verification method or for self-service password reset, the user must complete the verification within 10 minutes.
Ref: