<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with intelligent-mfa]]></title><description><![CDATA[A list of topics that have been tagged with intelligent-mfa]]></description><link>https://fusionauth.io/community/forum/tags/intelligent-mfa</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 20:47:33 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/intelligent-mfa.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[How does Intelligent MFA risk scoring work? Nearly all logins score MEDIUM risk]]></title><description><![CDATA[Disabling Individual Signals
<p dir="auto"><strong>Yes, individual signals can be disabled</strong> (but not weighted). Navigate to <strong>Tenants → Your Tenant → Security → Client risk configuration</strong> and enable the Customize risk signals toggle. You can then turn off individual signals, including DormantPassword.</p>
<p dir="auto">Disabled signals are excluded entirely from the composite risk calculation, so you can address the DormantPassword issue directly without needing a custom lambda.</p>
<p dir="auto"><strong>Important caveat from the documentation:</strong> "Disabling all signals sets the risk score to HIGH." Disable signals selectively, not everything.</p>
Risk Score Calculation Details
<p dir="auto">The exact weighting formula and thresholds for LOW/MEDIUM/HIGH composite scores are not fully documented. Individual signal scores combine into a composite score, and more HIGH signals raise the average, but the final result is bucketed as LOW, MEDIUM, or HIGH.</p>
Trusted Devices and Risk Policies
<p dir="auto"><strong>No, a trusted device does NOT automatically skip the challenge</strong> when using the built-in Intelligent MFA policies (ChallengeOnMediumRisk and ChallengeOnHighRisk).</p>
<p dir="auto"><strong>The risk policy still applies.</strong> From the <a href="https://fusionauth.io/docs/lifecycle/authenticate-users/contextual-multi-factor#with-an-enterprise-plan" rel="nofollow ugc">documentation</a>:</p>
<blockquote>
<p dir="auto">"The two risk policies ignore 'trust this device,' so users currently skipped by a trusted device are re-evaluated on risk and may be challenged."</p>
</blockquote>
<p dir="auto">A device marked as trusted can still trigger an MFA challenge if the composite risk score meets or exceeds the configured threshold.</p>
Recommended Next Steps

<strong>Disable the DormantPassword signal</strong> in your tenant's Client risk configuration
Monitor your risk score distribution after this change
Contact FusionAuth support if you need more details

]]></description><link>https://fusionauth.io/community/forum/topic/3150/how-does-intelligent-mfa-risk-scoring-work-nearly-all-logins-score-medium-risk</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3150/how-does-intelligent-mfa-risk-scoring-work-nearly-all-logins-score-medium-risk</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>