FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    Why are suspicious login emails sent on every login after upgrading to 1.69.2?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    suspicious login risk-signals intelligent-mfa upgrade
    1
    2
    15
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      After upgrading from an earlier version to FusionAuth 1.69.2, suspicious login emails are being sent on every login attempt, even for legitimate users logging in normally. This was not occurring before the upgrade.

      The volume of emails is high enough that it would be disruptive to users. As a temporary mitigation, the suspicious login email template has been disabled in the tenant configuration, but ideally this feature should be re-enabled for genuinely suspicious activity.

      What changed in recent versions that would cause suspicious login emails to trigger on every login?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        This behavior is likely due to changes introduced in FusionAuth 1.68.0 related to Intelligent MFA and Risk Signals.

        Starting in 1.68.0, FusionAuth uses a variety of "Risk Signals" to determine when to trigger the Suspicious Login email. The email is sent whenever any enabled risk signal returns a HIGH value. One common signal that can cause this is:

        • DormantPassword: This signal triggers when a user's password hasn't been changed "in the last few months." If your users do not regularly rotate their passwords, this risk signal could be flagging every login as suspicious.

        Solution

        You can fine-tune which Risk Signals are considered for your tenant:

        1. Navigate to Tenants > Edit Tenant > Security > Customize Risk Signals
        2. Review the enabled risk signals
        3. Consider toggling off the Dormant Password signal if password rotation is not part of your security model, or adjust other signals as appropriate for your use case

        Testing

        To verify this is the cause:

        • Try changing a user's password, then logging in again to see if the suspicious login email still triggers
        • Alternatively, disable the Dormant Password risk signal temporarily and test login behavior

        This should allow you to re-enable suspicious login notifications while avoiding false positives for normal login activity.

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post