Why are users receiving more suspicious login emails after upgrading FusionAuth?
-
After upgrading FusionAuth, users have been receiving a significantly higher number of "Suspicious activity detected on your account" emails when logging in. This wasn't occurring before the upgrade.
What could cause an increase in suspicious login detection after a FusionAuth upgrade? Are there new security features or risk detection mechanisms that might trigger more alerts?
-
This behavior changed due to the introduction of Intelligent MFA in FusionAuth 1.68, which significantly expanded the risk signals used to trigger suspicious login detection.
What Changed
Prior to version 1.68, suspicious login emails were primarily triggered by Impossible Travel detection (when a user appears to log in from geographically distant locations in an impossibly short time).
Starting in 1.68, FusionAuth added many more risk signals to the suspicious login detection system as part of the Intelligent MFA feature. This means more login scenarios now trigger the suspicious activity email.
How to Tune the Detection
If you want to restore the previous behavior or customize the risk detection to reduce false positives, you can configure this in your tenant settings:
- Navigate to Tenant > Edit > Security > Client Risk Config
- Configure the risk signals that should trigger suspicious login alerts
- To match the pre-1.68 behavior, set it to only trigger on "Impossible Travel"
You can customize these settings to find the right balance between security and user experience for your application.
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged