Skip to content

Auth0 identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Auth0, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Auth0 connector needs.

Checks (7)

severity: high User Without MFA fix difficulty: medium #

Enroll Auth0 users in multi-factor authentication

  1. Open Auth0 Dashboard > Security > Multi-factor Auth and enable a factor (e.g. Auth0 Guardian, WebAuthn)
  2. Set the MFA policy to require enrollment for all users
  3. Notify affected users to complete enrollment
  4. Note: mfa_enrolled is a best-effort signal — the user's multifactor[] list can remain stale after an admin MFA reset; confirm in the user's profile if in doubt

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Dormant User fix difficulty: easy #

Block or remove Auth0 accounts inactive for 90+ days

  1. Open Auth0 Dashboard > User Management > Users
  2. Filter by last login to identify dormant accounts
  3. Block or delete accounts that are no longer needed
  4. Document the review decision for compliance records

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: high Connection MFA Disabled fix difficulty: medium #

Enable MFA on database connections

  1. Open Auth0 Dashboard > Authentication > Database and select the connection
  2. Enable multi-factor authentication for the connection
  3. Verify enrollment for users authenticating through this connection

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Tenant MFA Not Enforced fix difficulty: medium #

Enforce MFA at the tenant level via a Guardian policy

  1. Open Auth0 Dashboard > Security > Multi-factor Auth
  2. Set the MFA policy to require MFA for all applications (or use Adaptive MFA on supported tiers)
  3. Save and verify the Guardian policy is active

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Weak Connection Password Policy fix difficulty: easy #

Raise the password policy on database connections to good or excellent

  1. Open Auth0 Dashboard > Authentication > Database and select the connection
  2. Open Password Policy and set strength to Good or Excellent
  3. Configure password history and dictionary checks
  4. Save and re-scan to confirm

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Connection Brute Force Protection Disabled fix difficulty: easy #

Enable brute-force protection on database connections

  1. Open Auth0 Dashboard > Security > Attack Protection > Brute-force Protection
  2. Enable brute-force protection and configure the block threshold
  3. Verify it applies to the affected database connection

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Long Tenant Session Lifetime fix difficulty: easy #

Reduce the tenant session lifetime to 168 hours (7 days) or less

  1. Open Auth0 Dashboard > Settings > Advanced > Login Session Management
  2. Set the Inactivity timeout and Require log in after to a value of 168 hours or less
  3. Save and verify the new session limits

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.5 DORA (SaaS Security) DORA-9.5

More Auth0 checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial