<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How does Intelligent MFA risk scoring work? Nearly all logins score MEDIUM risk]]></title><description><![CDATA[<p dir="auto">We recently enabled MFA (email + authenticator) and are exploring Intelligent MFA to improve UX for legitimate users. After enabling MFA debugging for about a week, we've observed the following pattern:</p>
<ul>
<li>~5k login events captured</li>
<li>All but a very few events show composite risk as MEDIUM</li>
<li>Those few events show HIGH risk</li>
<li>Zero events show LOW risk</li>
</ul>
<p dir="auto">This means:</p>
<ul>
<li>Enabling <code>ChallengeOnMediumRisk</code> would challenge everyone, all the time</li>
<li>Enabling <code>ChallengeOnHighRisk</code> would challenge almost nobody</li>
</ul>
<p dir="auto">We suspect the <code>DormantPassword</code> signal is pushing many risk levels to MEDIUM because it frequently scores HIGH. According to NIST guidelines, we shouldn't require password changes anyway—just strong, unique passwords.</p>
<p dir="auto"><strong>Questions:</strong></p>
<ol>
<li><strong>Can individual signals be weighted or disabled?</strong> Can we turn off <code>DormantPassword</code> specifically?</li>
<li><strong>Does a single HIGH signal always make composite risk at least MEDIUM?</strong> What does it take to score LOW?</li>
<li><strong>Does a trusted device skip the challenge regardless of risk score, or does the risk policy still apply?</strong></li>
<li><strong>Does a missing signal count differently from a LOW one in the composite?</strong></li>
</ol>
]]></description><link>https://fusionauth.io/community/forum/topic/3150/how-does-intelligent-mfa-risk-scoring-work-nearly-all-logins-score-medium-risk</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 20:46:29 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3150.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Sep 2026 06:20:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How does Intelligent MFA risk scoring work? Nearly all logins score MEDIUM risk on Mon, 28 Sep 2026 17:14:51 GMT]]></title><description><![CDATA[<h2>Disabling Individual Signals</h2>
<p dir="auto"><strong>Yes, individual signals can be disabled</strong> (but not weighted). Navigate to <strong>Tenants → Your Tenant → Security → Client risk configuration</strong> and enable the <code>Customize risk signals</code> toggle. You can then turn off individual signals, including <code>DormantPassword</code>.</p>
<p dir="auto">Disabled signals are excluded entirely from the composite risk calculation, so you can address the <code>DormantPassword</code> issue directly without needing a custom lambda.</p>
<p dir="auto"><strong>Important caveat from the documentation:</strong> <em>"Disabling all signals sets the risk score to HIGH."</em> Disable signals selectively, not everything.</p>
<h2>Risk Score Calculation Details</h2>
<p dir="auto">The exact weighting formula and thresholds for LOW/MEDIUM/HIGH composite scores are not fully documented. Individual signal scores combine into a composite score, and more HIGH signals raise the average, but the final result is bucketed as LOW, MEDIUM, or HIGH.</p>
<h2>Trusted Devices and Risk Policies</h2>
<p dir="auto"><strong>No, a trusted device does NOT automatically skip the challenge</strong> when using the built-in Intelligent MFA policies (<code>ChallengeOnMediumRisk</code> and <code>ChallengeOnHighRisk</code>).</p>
<p dir="auto"><strong>The risk policy still applies.</strong> From the <a href="https://fusionauth.io/docs/lifecycle/authenticate-users/contextual-multi-factor#with-an-enterprise-plan" rel="nofollow ugc">documentation</a>:</p>
<blockquote>
<p dir="auto">"The two risk policies ignore 'trust this device,' so users currently skipped by a trusted device are re-evaluated on risk and may be challenged."</p>
</blockquote>
<p dir="auto">A device marked as trusted can still trigger an MFA challenge if the composite risk score meets or exceeds the configured threshold.</p>
<h2>Recommended Next Steps</h2>
<ol>
<li><strong>Disable the <code>DormantPassword</code> signal</strong> in your tenant's Client risk configuration</li>
<li>Monitor your risk score distribution after this change</li>
<li>Contact FusionAuth support if you need more details</li>
</ol>
]]></description><link>https://fusionauth.io/community/forum/post/8639</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8639</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Mon, 28 Sep 2026 17:14:51 GMT</pubDate></item></channel></rss>