Yes, individual signals can be disabled (but not weighted). Navigate to Tenants → Your Tenant → Security → Client risk configuration and enable the Customize risk signals toggle. You can then turn off individual signals, including DormantPassword.
Disabled signals are excluded entirely from the composite risk calculation, so you can address the DormantPassword issue directly without needing a custom lambda.
Important caveat from the documentation: "Disabling all signals sets the risk score to HIGH." Disable signals selectively, not everything.
Risk Score Calculation DetailsThe exact weighting formula and thresholds for LOW/MEDIUM/HIGH composite scores are not fully documented. Individual signal scores combine into a composite score, and more HIGH signals raise the average, but the final result is bucketed as LOW, MEDIUM, or HIGH.
Trusted Devices and Risk PoliciesNo, a trusted device does NOT automatically skip the challenge when using the built-in Intelligent MFA policies (ChallengeOnMediumRisk and ChallengeOnHighRisk).
The risk policy still applies. From the documentation:
"The two risk policies ignore 'trust this device,' so users currently skipped by a trusted device are re-evaluated on risk and may be challenged."
A device marked as trusted can still trigger an MFA challenge if the composite risk score meets or exceeds the configured threshold.
Recommended Next Steps Disable the DormantPassword signal in your tenant's Client risk configuration Monitor your risk score distribution after this change Contact FusionAuth support if you need more details