-
We recently enabled MFA (email + authenticator) and are exploring Intelligent MFA to improve UX for legitimate users. After enabling MFA debugging for about a week, we've observed the following pattern:
- ~5k login events captured
- All but a very few events show composite risk as MEDIUM
- Those few events show HIGH risk
- Zero events show LOW risk
This means:
- Enabling
ChallengeOnMediumRiskwould challenge everyone, all the time - Enabling
ChallengeOnHighRiskwould challenge almost nobody
We suspect the
DormantPasswordsignal is pushing many risk levels to MEDIUM because it frequently scores HIGH. According to NIST guidelines, we shouldn't require password changes anyway—just strong, unique passwords.Questions:
- Can individual signals be weighted or disabled? Can we turn off
DormantPasswordspecifically? - Does a single HIGH signal always make composite risk at least MEDIUM? What does it take to score LOW?
- Does a trusted device skip the challenge regardless of risk score, or does the risk policy still apply?
- Does a missing signal count differently from a LOW one in the composite?
-
Disabling Individual Signals
Yes, individual signals can be disabled (but not weighted). Navigate to Tenants → Your Tenant → Security → Client risk configuration and enable the
Customize risk signalstoggle. You can then turn off individual signals, includingDormantPassword.Disabled signals are excluded entirely from the composite risk calculation, so you can address the
DormantPasswordissue directly without needing a custom lambda.Important caveat from the documentation: "Disabling all signals sets the risk score to HIGH." Disable signals selectively, not everything.
Risk Score Calculation Details
The exact weighting formula and thresholds for LOW/MEDIUM/HIGH composite scores are not fully documented. Individual signal scores combine into a composite score, and more HIGH signals raise the average, but the final result is bucketed as LOW, MEDIUM, or HIGH.
Trusted Devices and Risk Policies
No, a trusted device does NOT automatically skip the challenge when using the built-in Intelligent MFA policies (
ChallengeOnMediumRiskandChallengeOnHighRisk).The risk policy still applies. From the documentation:
"The two risk policies ignore 'trust this device,' so users currently skipped by a trusted device are re-evaluated on risk and may be challenged."
A device marked as trusted can still trigger an MFA challenge if the composite risk score meets or exceeds the configured threshold.
Recommended Next Steps
- Disable the
DormantPasswordsignal in your tenant's Client risk configuration - Monitor your risk score distribution after this change
- Contact FusionAuth support if you need more details
- Disable the
-
D dan has marked this topic as solved
-
D dan moved this topic from Hidden