<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with suspicious]]></title><description><![CDATA[A list of topics that have been tagged with suspicious]]></description><link>https://fusionauth.io/community/forum/tags/suspicious</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 07:03:11 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/suspicious.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[Why are suspicious login emails sent on every login after upgrading to 1.69.2?]]></title><description><![CDATA[<p dir="auto">This behavior is likely due to changes introduced in <strong>FusionAuth 1.68.0</strong> related to <strong>Intelligent MFA</strong> and <strong>Risk Signals</strong>.</p>
<p dir="auto">Starting in 1.68.0, FusionAuth uses a variety of "Risk Signals" to determine when to trigger the Suspicious Login email. The email is sent whenever any enabled risk signal returns a HIGH value. One common signal that can cause this is:</p>

<strong>DormantPassword</strong>: This signal triggers when a user's password hasn't been changed "in the last few months." If your users do not regularly rotate their passwords, this risk signal could be flagging every login as suspicious.

Solution
<p dir="auto">You can fine-tune which Risk Signals are considered for your tenant:</p>

Navigate to <strong>Tenants &gt; Edit Tenant &gt; Security &gt; Customize Risk Signals</strong>
Review the enabled risk signals
Consider toggling off the <strong>Dormant Password</strong> signal if password rotation is not part of your security model, or adjust other signals as appropriate for your use case

Testing
<p dir="auto">To verify this is the cause:</p>

Try changing a user's password, then logging in again to see if the suspicious login email still triggers
Alternatively, disable the Dormant Password risk signal temporarily and test login behavior

<p dir="auto">This should allow you to re-enable suspicious login notifications while avoiding false positives for normal login activity.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3178/why-are-suspicious-login-emails-sent-on-every-login-after-upgrading-to-1-69-2</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3178/why-are-suspicious-login-emails-sent-on-every-login-after-upgrading-to-1-69-2</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>