FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    How does Intelligent MFA risk scoring work? Nearly all logins score MEDIUM risk

    Scheduled Pinned Locked Moved Solved
    Q&A
    intelligent-mfa mfa risk-signals dormant password
    1
    2
    15
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by dan

      We recently enabled MFA (email + authenticator) and are exploring Intelligent MFA to improve UX for legitimate users. After enabling MFA debugging for about a week, we've observed the following pattern:

      • ~5k login events captured
      • All but a very few events show composite risk as MEDIUM
      • Those few events show HIGH risk
      • Zero events show LOW risk

      This means:

      • Enabling ChallengeOnMediumRisk would challenge everyone, all the time
      • Enabling ChallengeOnHighRisk would challenge almost nobody

      We suspect the DormantPassword signal is pushing many risk levels to MEDIUM because it frequently scores HIGH. According to NIST guidelines, we shouldn't require password changes anyway—just strong, unique passwords.

      Questions:

      1. Can individual signals be weighted or disabled? Can we turn off DormantPassword specifically?
      2. Does a single HIGH signal always make composite risk at least MEDIUM? What does it take to score LOW?
      3. Does a trusted device skip the challenge regardless of risk score, or does the risk policy still apply?
      4. Does a missing signal count differently from a LOW one in the composite?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by dan

        Disabling Individual Signals

        Yes, individual signals can be disabled (but not weighted). Navigate to Tenants → Your Tenant → Security → Client risk configuration and enable the Customize risk signals toggle. You can then turn off individual signals, including DormantPassword.

        Disabled signals are excluded entirely from the composite risk calculation, so you can address the DormantPassword issue directly without needing a custom lambda.

        Important caveat from the documentation: "Disabling all signals sets the risk score to HIGH." Disable signals selectively, not everything.

        Risk Score Calculation Details

        The exact weighting formula and thresholds for LOW/MEDIUM/HIGH composite scores are not fully documented. Individual signal scores combine into a composite score, and more HIGH signals raise the average, but the final result is bucketed as LOW, MEDIUM, or HIGH.

        Trusted Devices and Risk Policies

        No, a trusted device does NOT automatically skip the challenge when using the built-in Intelligent MFA policies (ChallengeOnMediumRisk and ChallengeOnHighRisk).

        The risk policy still applies. From the documentation:

        "The two risk policies ignore 'trust this device,' so users currently skipped by a trusted device are re-evaluated on risk and may be challenged."

        A device marked as trusted can still trigger an MFA challenge if the composite risk score meets or exceeds the configured threshold.

        Recommended Next Steps

        1. Disable the DormantPassword signal in your tenant's Client risk configuration
        2. Monitor your risk score distribution after this change
        3. Contact FusionAuth support if you need more details

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Hidden
        • First post
          Last post