<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Why are users receiving more suspicious login emails after upgrading FusionAuth?]]></title><description><![CDATA[<p dir="auto">After upgrading FusionAuth, users have been receiving a significantly higher number of "Suspicious activity detected on your account" emails when logging in. This wasn't occurring before the upgrade.</p>
<p dir="auto">What could cause an increase in suspicious login detection after a FusionAuth upgrade? Are there new security features or risk detection mechanisms that might trigger more alerts?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3182/why-are-users-receiving-more-suspicious-login-emails-after-upgrading-fusionauth</link><generator>RSS for Node</generator><lastBuildDate>Thu, 08 Oct 2026 01:01:54 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3182.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 01 Oct 2026 15:47:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Why are users receiving more suspicious login emails after upgrading FusionAuth? on Thu, 01 Oct 2026 15:47:57 GMT]]></title><description><![CDATA[<p dir="auto">This behavior changed due to the introduction of <strong>Intelligent MFA</strong> in FusionAuth 1.68, which significantly expanded the risk signals used to trigger suspicious login detection.</p>
<h2>What Changed</h2>
<p dir="auto">Prior to version 1.68, suspicious login emails were primarily triggered by <strong>Impossible Travel</strong> detection (when a user appears to log in from geographically distant locations in an impossibly short time).</p>
<p dir="auto">Starting in 1.68, FusionAuth added many more risk signals to the suspicious login detection system as part of the Intelligent MFA feature. This means more login scenarios now trigger the suspicious activity email.</p>
<h2>How to Tune the Detection</h2>
<p dir="auto">If you want to restore the previous behavior or customize the risk detection to reduce false positives, you can configure this in your tenant settings:</p>
<ol>
<li>Navigate to <strong>Tenant &gt; Edit &gt; Security &gt; Client Risk Config</strong></li>
<li>Configure the risk signals that should trigger suspicious login alerts</li>
<li>To match the pre-1.68 behavior, set it to only trigger on <strong>"Impossible Travel"</strong></li>
</ol>
<p dir="auto">You can customize these settings to find the right balance between security and user experience for your application.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8701</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8701</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Thu, 01 Oct 2026 15:47:57 GMT</pubDate></item></channel></rss>