User Account is Not Blocked When 'Block compromised user accounts' Feature is Enabled
Last Updated:
Overview
This article explains why there is no indication that a user is blocked after activating the Block Compromised user accounts setting under Response Block Settings in Attack protection - Breached Password detection. Logins attempts are blocked successfully by this feature, but the failed authentications are logged in the Auth0 logs as "type": "pwd_leak". There is no additional indication on the account that it is blocked.
Applies To
- Blocked compromised user accounts
- Response Block Settings
Solution
This behavior is functioning as designed. The Breach Password Detection feature checks the user's password during every log-in. There is no flag in the user's account that can be cleared as in other scenarios, such as a Brute Force protection. When reviewing the user's account, it does not appear as blocked. However, the login will continue to be blocked until the user changes their password.