FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    Why are users receiving more suspicious login emails after upgrading FusionAuth?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    upgrade security suspicious login intelligent-mfa
    1
    2
    3
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      After upgrading FusionAuth, users have been receiving a significantly higher number of "Suspicious activity detected on your account" emails when logging in. This wasn't occurring before the upgrade.

      What could cause an increase in suspicious login detection after a FusionAuth upgrade? Are there new security features or risk detection mechanisms that might trigger more alerts?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        This behavior changed due to the introduction of Intelligent MFA in FusionAuth 1.68, which significantly expanded the risk signals used to trigger suspicious login detection.

        What Changed

        Prior to version 1.68, suspicious login emails were primarily triggered by Impossible Travel detection (when a user appears to log in from geographically distant locations in an impossibly short time).

        Starting in 1.68, FusionAuth added many more risk signals to the suspicious login detection system as part of the Intelligent MFA feature. This means more login scenarios now trigger the suspicious activity email.

        How to Tune the Detection

        If you want to restore the previous behavior or customize the risk detection to reduce false positives, you can configure this in your tenant settings:

        1. Navigate to Tenant > Edit > Security > Client Risk Config
        2. Configure the risk signals that should trigger suspicious login alerts
        3. To match the pre-1.68 behavior, set it to only trigger on "Impossible Travel"

        You can customize these settings to find the right balance between security and user experience for your application.

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post