Breached Password Detection Not Triggering Despite Being Turned On
Last Updated:
Overview
This article explains why a user may be able to log in successfully after trying to log in with a known breached password by following the Verify detection configuration steps for the Breached Password Detection feature.
Applies To
- Breached Password Detection
Cause
Misconfiguration
This can occur if the Breached Password toggle is enabled, but no "Response" option is selected in the Breached Password Detection settings.
The Credential does not match the breached identifier + password pair
Breached Password Detection detects pairs of breached identifiers (email/username) and passwords.
Using the breached password alone will not trigger the detection.
Solution
Ensure that the relevant Responses are enabled in the settings. If everything is disabled, Breached Password Detection will not trigger, even if the feature is turned on at the top of the page.