Testing the Auth0 Breached Password Detection Feature
Last Updated:
Overview
Administrators testing the Auth0 breached password detection feature can use specific test credentials to verify the configuration. Using designated test passwords allows administrators to confirm that Auth0 successfully blocks compromised credentials during signup, password reset, and login events.
Applies To
- Auth0
- Breached Password Detection
Solution
How is the Auth0 breached password detection feature tested?
Configure the breached password detection settings and use designated test passwords to verify the feature blocks compromised credentials using the following process.
- Enable breached password detection and configure it to block compromised credential use upon signup, password reset, and login.
- Enter any Auth0 database user email with the password
Paaf213XXYYZZ,Paat739!!WWXXYYZZ, or any password starting withAUTH0-TEST-. Auth0 rejects the password reset and signup attempts. - Test the login detection by temporarily disabling either the sign-up or the password reset response options for breached password detection while keeping the login response enabled. Without disabling one of the first two, you wouldn't be able to set a user's password to a designated test one.
- Set a user password to one of the test passwords.
- Attempt to log in to confirm that Auth0 prevents the login.