Breached Password Detection Scope for Database Connections and Tenant Administrators
Last Updated:
Overview
This article explains the scope of the Breached Password Detection (BPD) feature and clarifies which user types are protected by this security measure within a tenant.
Applies To
- Breached Password Detection (BPD)
- Database Connection
- Tenant Administrators
Solution
Breached Password Detection applies to specific user sets based on the connection type and the application being accessed:
-
BPD covers all users stored in a Database Connection within the tenant.
-
This coverage includes customers (end users) and any administrative users created for internal applications.
-
BPD does not apply to Tenant Administrators signing in to the Auth0 Dashboard via manage.auth0.com using a username and password.
-
Dashboard access for Tenant Administrators is managed by an internal authentication system that utilizes separate built-in security protections to safeguard the platform.