Breached Password Detection Not Triggering Despite Being Turned On

Overview

This article explains why a user may be able to log in successfully after trying to log in with a known breached password by following the Verify detection configuration steps for the Breached Password Detection feature.

Applies To

  • Breached Password Detection

Cause

Misconfiguration

This can occur if the Breached Password toggle is enabled, but no "Response" option is selected in the Breached Password Detection settings.

 

The Credential does not match the breached identifier + password pair

Breached Password Detection detects pairs of breached identifiers (email/username) and passwords.

Using the breached password alone will not trigger the detection.

Solution

Ensure that the relevant Responses are enabled in the settings. If everything is disabled, Breached Password Detection will not trigger, even if the feature is turned on at the top of the page.

 

Block compromised credential use upon signup setting

Recommended content

No recommended content found...