What's new in Risk Engine
SecureAuth Risk Engine judges how likely it is that each sign-in is really the person it claims to be. It weighs signals like whether the device is one they have used before, whether the location and time of day fit their pattern, and whether the IP address looks trustworthy.
When everything looks normal, the user signs in without interruption. When something looks off, they are asked for a second factor. The result is fewer interruptions for legitimate users, with the extra checks concentrated where the risk actually is.
Each product reports that judgement as a confidence score, called the Level of Assurance (LOA), and you set the threshold at which a second factor is required. This page collects Risk Engine updates from April 15, 2026 onward, newest first.
How to read this page
The Risk Engine is shared across SecureAuth Connect, SecureAuth IdP, and Arculix, and most updates reach all three. An entry carries a label only when a change is limited to one product:
- SecureAuth Connect for SecureAuth Connect only.
- SA IdP for SecureAuth IdP only.
- Arculix for Arculix only.
An entry with no label applies to all three.
Products band the confidence score differently, so the same number does not always mean the same thing. Check the threshold guidance for the product you run.
Some scoring changes take effect only after the machine learning models retrain. Each entry says so where it applies.
August 2026
New features
-
SecureAuth Connect Risk Intelligence dashboard for your tenant. You can now review Risk Engine activity for your own tenant. The Overview tab carries the cutoff, missing-fingerprint, and low-confidence stat cards, the average friction and confidence cards, six anomaly-detection charts, and the authentication transactions table. The Risk Assessment tab covers risky users, risky IP addresses, burst logins, and credential stuffing patterns. There is no User Activity tab and no per-user drill-down. Go to Analytics > Risk Intelligence; the entry appears only if your tenant is licensed for the Risk Engine and the dashboard is enabled for you. See Risk Intelligence dashboard.
-
SA IdP More detail on the User Activity tab. The per-user view adds a unique IP count and last login. The transactions grid gains Device and City columns, with the city linking to exact coordinates on a map, and copy buttons on shortened IPv6 and fingerprint values. Columns are sortable on the per-user grid only. This tab exists on the SecureAuth IdP dashboard only.
Behavior changes
-
A first sign-in to a new application or timezone no longer scores worst case. Expect slightly higher confidence scores for users hitting a new application or travelling into a new timezone. Takes effect only after the affected models are retrained.
-
Browser and operating system now feed the device model correctly. The device model had been training on an empty browser value while scoring resolved a real one. That gap is now closed. Requires retraining to take effect, and device sub-scores may shift on the first training cycle afterwards.
-
Two behavioral models retired. The Browser Trust (BT) analyzer no longer runs, which changes no scores because it was already inactive. A second model was active, so behavioral scores may shift where it applied.
Bug fixes
-
SA IdP Assurance and friction figures on the User Activity tab now match Overview. They previously counted sign-ins with no device fingerprint, which dragged assurance down and pushed friction up. Expect these numbers to move on the User Activity tab. The previous values were wrong, not the new ones. Duplicate cards that disagreed with each other are collapsed into one each, and the Incomplete and Missing Fingerprint tiles are now genuinely distinct.
-
Browser, operating system, and device details display. The transactions grid showed every browser as
Unknown, and the devices and browsers breakdown bucketed everything the same way. Details now populate, so you can tell what a user signed in from. They reflect what was captured the first time a fingerprint was seen, not its current state. -
Prior-transaction lookup now checks tenant and user. Closes a missing authorization check in continuous authentication. No client sends that value today, so nothing was exposed.
-
Dashboard alignment. The transactions table sat slightly inside the cards above it, and stat rows left gaps instead of filling the row.
Performance
-
Authentication transactions loads faster. The table no longer counts every matching row on each load. Counts are capped at 10,000, so a larger result shows as
10,000+rather than an exact total. Counts below the cap stay exact, and filtering by user gives an exact count at any size. -
Dashboard analytics run faster. Several dashboard figures that could take over a minute now load quickly. A further improvement to the cutoff figures is still to come.
Smart Fingerprint
Smart Fingerprint is the collector that gathers device and browser details at sign-in, so the Risk Engine can tell a familiar device from a new one.
-
Fewer real users flagged as automated browsers. A headless browser runs under script control with no visible window, a common way to automate sign-in attempts at scale, so the Risk Engine treats it as a risk signal. Real users whose window simply happened to be hidden while it loaded, such as a VPN client popup or an in-app browser on Android, were sometimes flagged the same way. These now score normally, and genuine headless browsers are still detected.
-
Collector version recorded with each fingerprint. Helps support trace a problem to a specific release. Fingerprints captured before this change report
unknown. -
Dependency security updates. Further security vulnerabilities remediated across the collector's dependencies.
July 2026
New features
-
SA IdP Bypass Reason on policy sign-ins. The Authentication Transactions grid adds a Bypass Reason column showing which adaptive policy let a sign-in skip MFA, for example Trusted Network, Geo-Velocity, Group Override, or Transparent Single Sign-on (TSSO). Rows that are not policy sign-ins show a dash. The column fills in only once your identity provider starts sending the reason, and only the SecureAuth IdP identity provider does so today.
-
Dark mode on the dashboard. A full dark theme covering charts, maps, and progress indicators, with a toggle to switch between light and dark.
Behavior changes
- Repeat high-risk sign-ins no longer build trust. When MFA is skipped because the score was already above your threshold, that sign-in keeps known IP and user pairings current but no longer teaches the models anything new. Read this as tighter scoring rather than a regression: sub-scores for repeat over-threshold sign-ins may build trust more slowly than before.
Smart Fingerprint
-
Balanced collection mode. A new middle option between the full and light collection profiles. It keeps the strongest device signals and skips only the slow checks, which cuts page-load time where sign-in latency matters.
-
Fewer false headless-browser flags. Automated browsers that run with a visible window are no longer scored as headless, which reduces spurious Headless Browser risk signals.
-
Security updates. Known security vulnerabilities remediated across the collector's dependencies.
June 2026
New features
- Organization and application names on the dashboard. The transactions table and charts show display names instead of raw identifiers, so you no longer need a separate lookup.
Behavior changes
- A timezone match no longer masks a first sign-in. A timezone match no longer overrides the "not enough history yet" state on a very first sign-in, which avoids a misleading initial score.
Bug fixes
- Dashboard counter accuracy. Counters are built from the risk score value itself rather than matching text. Total Login Attempts uses thousands separators, and an empty date range reads as no data instead of zero.
Performance
- Faster dashboards. The heaviest dashboard charts load faster.
May 2026
New features
- QR code sign-ins are scored. QR code is now a recognized authentication method with its own scoring tier.
Bug fixes
-
Dashboard chart accuracy. The no-data placeholder is no longer counted in the average LOA and friction charts, and friction rate is calculated over approved scored sign-ins. User search is faster and shows display names on drill-down.
-
IP address handling. IPv6 handling and IP normalization on ingest are improved, and IP lookups are faster. The anonymous proxy signal, which was occasionally not applied to the score, is now reflected correctly.
-
Policy events preserved. Policy events are no longer dropped during an authentication status call, and policy signals are excluded from analyzer baselines so they do not skew what the models learn.
-
Location assessment with partial coordinates. A sign-in with only a latitude or only a longitude reports the assessment as unavailable instead of failing.
-
Cache correctness. A cache key collision that could return a stale or incorrect result is fixed.
-
Administrator edit and delete hardening. These actions no longer fail with a server error in edge cases.
April 2026
New features
-
Turn individual risk signals on or off per tenant. Individual signals can be silenced for a tenant or an organization on the Filtered Risk Indicators page, without losing the others alongside them.
-
Tune how strongly each risk signal counts. Every signal now has a weight that scales its contribution to the confidence score, managed on the Risk Indicators page. Weights apply to all tenants in this release.
Behavior changes
- Device fingerprint scoring rebalanced. The Headless Browser signal contributes less, and Suspicious Browser Fingerprinting is active again at a low weight. Device scores may shift slightly.
What changed for administrators
| Goal | How to do it now |
|---|---|
| Silence one noisy risk signal. | Turn the signal off on the Filtered Risk Indicators page. |
| Change how strongly a signal counts toward the confidence score. | Edit the weight on the Risk Indicators page. |
| Stop a hard block (cutoff). | Use Cutoff Exclusions, which is unchanged. Turning a signal off does not stop a cutoff tied to it. |
Configuration changes take effect within a couple of minutes.
See also
- Risk Engine: Smarter security in action
- Risk analyzers
- Risk Intelligence dashboard
- Configure the Level of Assurance (LOA) threshold
For SecureAuth Identity Platform, where LOA scores appear under Dashboard > Login Data > LOA Score and the provider is configured under Risk and Assurance Providers > Assurance Provider: