Brute-Force Protection (2024)

Brute-force protection safeguards against a single IP address attacking a single user account. When a given IP address tries and fails multiple times to log in as the same user, brute-force protection:

  • Blocks the suspicious IP address from logging in as that user.

  • Sends a notification to the affected user.

Brute-force protection safeguards apply to all users, including tenant administrators. Ensure your tenant has a secondary administrator in order to unblock other administrator accounts.

If an IP address is blocked due to brute-force protection, it remains blocked until one of these events occurs:

In cases where a user's account (email) is linked through multiple connections, such as an OTP account and a database account, and they change their password on only one, the block will not be removed. The user must change their passwords on each account (connection type).

Configure brute-force protection

Auth0 strongly recommends that you do not disable brute-force protection for the connection. If you disable it, you can enable it again using the Dashboard.

Enabling attack protection features without any response settings enabled activates Monitoring mode, which records related events in your tenant log only. To learn more, read View Attack Protection Log Events.

  1. Go to Dashboard > Security > Attack Protection and select Brute-force Protection. Enable the toggle at the top of the page if it is disabled.

    Brute-Force Protection (1)
  2. In the Detection section:

    1. Under Brute Force Threshold, select Default to use the standard limit of 10 maximum attempts, or select Custom to set the limit of maximum attempts to a value between 1 and 100.

    2. Under Manage IP Addresses, enter the list of trusted IP addresses in the IP AllowList field. Brute-force protection will not be enforced for login attempts originating from these IP addresses.

  3. In the Response section:

    1. Under Block Settings, enable the Block Brute-force Logins toggle to block attempts from suspicious IP addresses to safeguard against brute-force attacks that occur from a single IP address and target a single user account.

    2. Under Block Settings, enable Account Lockout to trigger blocks irrespective of IP address. When this setting is enabled and a user consecutively attempts and fails to login, future attempts to log in from that user from any IP address will be blocked. You can adjust maximum attempts under Brute Force Threshold. By default, the Account Lockout toggle is disabled.

    3. Under Notifications, enable the Send notifications to the affected users toggle to send an email notification to the user when their account has been blocked.

  4. Click Save.

Notifications

If Send notifications to the affected users is enabled, Auth0 sends an SMS or email notification to a user when their account has been blocked.

SMS

Auth0 sends an SMS to the user if they use a phone identifier in the login flow. SMS notifications are limited at a maximum of 1 per hour per identifier.

Email

Auth0 sends an email to the user if they use a non-phone identifier in the login flow. Email notifications are limited at a maximum of 1 per hour per unique IP address.

By default, email notifications contain a link that allows the user to unblock their account. To learn more, read Customize Blocked Account Emails.

Special use cases

Because brute-force protection depends on the IP address of the user, the following use cases require additional configuration:

  • ROPG on the backend: Using this call does not get the IP address of the user; however, to make brute-force protection work correctly, you can configure your application and send the IP address of the user as part of the request.

  • User authentication from the same IP address: Users who are behind a proxy are more likely to reach set limits and trigger brute-force protection.

To learn more, read Avoid Common Issues with Resource Owner Password Flow and Attack Protection.

Learn more

Brute-Force Protection (2024)
Top Articles
Joola - Connect, save, and prosper together
A Snapdragon-only Surface Pro is bad news for Intel
Jail Inquiry | Polk County Sheriff's Office
Algebra Calculator Mathway
What are Dietary Reference Intakes?
The Realcaca Girl Leaked
Nm Remote Access
What is international trade and explain its types?
Barstool Sports Gif
Wnem Radar
Thotsbook Com
Buying risk?
What Time Chase Close Saturday
Foodland Weekly Ad Waxahachie Tx
Christina Khalil Forum
Midlife Crisis F95Zone
Michigan cannot fire coach Sherrone Moore for cause for known NCAA violations in sign-stealing case
라이키 유출
Spider-Man: Across The Spider-Verse Showtimes Near Marcus Bay Park Cinema
2020 Military Pay Charts – Officer & Enlisted Pay Scales (3.1% Raise)
Accident On The 210 Freeway Today
Between Friends Comic Strip Today
Gina Wilson All Things Algebra Unit 2 Homework 8
Somewhere In Queens Showtimes Near The Maple Theater
Imouto Wa Gal Kawaii - Episode 2
Scheuren maar: Ford Sierra Cosworth naar de veiling
Synergy Grand Rapids Public Schools
Klsports Complex Belmont Photos
Nottingham Forest News Now
Downtown Dispensary Promo Code
Yayo - RimWorld Wiki
By.association.only - Watsonville - Book Online - Prices, Reviews, Photos
Maths Open Ref
Osrs Important Letter
Chattanooga Booking Report
Frostbite Blaster
Darrell Waltrip Off Road Center
Spinning Gold Showtimes Near Emagine Birch Run
Craigslist Greencastle
New York Rangers Hfboards
Build-A-Team: Putting together the best Cathedral basketball team
Studio 22 Nashville Review
manhattan cars & trucks - by owner - craigslist
Actor and beloved baritone James Earl Jones dies at 93
Mauston O'reilly's
Willkommen an der Uni Würzburg | WueStart
bot .com Project by super soph
Google Flights Missoula
Www Ventusky
Latest Posts
Article information

Author: Annamae Dooley

Last Updated:

Views: 5355

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.