<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Why are suspicious login emails sent on every login after upgrading to 1.69.2?]]></title><description><![CDATA[<p dir="auto">After upgrading from an earlier version to FusionAuth 1.69.2, suspicious login emails are being sent on every login attempt, even for legitimate users logging in normally. This was not occurring before the upgrade.</p>
<p dir="auto">The volume of emails is high enough that it would be disruptive to users. As a temporary mitigation, the suspicious login email template has been disabled in the tenant configuration, but ideally this feature should be re-enabled for genuinely suspicious activity.</p>
<p dir="auto">What changed in recent versions that would cause suspicious login emails to trigger on every login?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3178/why-are-suspicious-login-emails-sent-on-every-login-after-upgrading-to-1-69-2</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 23:21:53 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3178.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 Sep 2026 19:53:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Why are suspicious login emails sent on every login after upgrading to 1.69.2? on Wed, 30 Sep 2026 19:53:32 GMT]]></title><description><![CDATA[<p dir="auto">This behavior is likely due to changes introduced in <strong>FusionAuth 1.68.0</strong> related to <strong>Intelligent MFA</strong> and <strong>Risk Signals</strong>.</p>
<p dir="auto">Starting in 1.68.0, FusionAuth uses a variety of "Risk Signals" to determine when to trigger the Suspicious Login email. The email is sent whenever any enabled risk signal returns a <code>HIGH</code> value. One common signal that can cause this is:</p>
<ul>
<li><strong>DormantPassword</strong>: This signal triggers when a user's password hasn't been changed "in the last few months." If your users do not regularly rotate their passwords, this risk signal could be flagging every login as suspicious.</li>
</ul>
<h2>Solution</h2>
<p dir="auto">You can fine-tune which Risk Signals are considered for your tenant:</p>
<ol>
<li>Navigate to <strong>Tenants &gt; Edit Tenant &gt; Security &gt; Customize Risk Signals</strong></li>
<li>Review the enabled risk signals</li>
<li>Consider toggling off the <strong>Dormant Password</strong> signal if password rotation is not part of your security model, or adjust other signals as appropriate for your use case</li>
</ol>
<h2>Testing</h2>
<p dir="auto">To verify this is the cause:</p>
<ul>
<li>Try changing a user's password, then logging in again to see if the suspicious login email still triggers</li>
<li>Alternatively, disable the Dormant Password risk signal temporarily and test login behavior</li>
</ul>
<p dir="auto">This should allow you to re-enable suspicious login notifications while avoiding false positives for normal login activity.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8693</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8693</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Wed, 30 Sep 2026 19:53:32 GMT</pubDate></item></channel></rss>