Testing the Auth0 Breached Password Detection Feature

Overview

Administrators testing the Auth0 breached password detection feature can use specific test credentials to verify the configuration. Using designated test passwords allows administrators to confirm that Auth0 successfully blocks compromised credentials during signup, password reset, and login events.

Applies To

  • Auth0
  • Breached Password Detection

Solution

How is the Auth0 breached password detection feature tested?

Configure the breached password detection settings and use designated test passwords to verify the feature blocks compromised credentials using the following process.

  1. Enable breached password detection and configure it to block compromised credential use upon signup, password reset, and login.
  2. Enter any Auth0 database user email with the password Paaf213XXYYZZ, Paat739!!WWXXYYZZ, or any password starting with AUTH0-TEST-. Auth0 rejects the password reset and signup attempts.
  3. Test the login detection by temporarily disabling either the sign-up or the password reset response options for breached password detection while keeping the login response enabled. Without disabling one of the first two, you wouldn't be able to set a user's password to a designated test one.
  4. Set a user password to one of the test passwords.
  5. Attempt to log in to confirm that Auth0 prevents the login.

 

Related References

Recommended content

No recommended content found...