Risk-Based Authentication Software Resources
Articles, Glossary Terms, Discussions, and Reports to expand your knowledge on Risk-Based Authentication Software
Resource pages are designed to give you a cross-section of information we have on specific categories. You'll find articles from our experts, feature definitions, discussions from users like you, and reports from industry data.
Risk-Based Authentication Software Articles
What is User Authentication? Strengthening Digital Security
What is Multi-Factor Authentication (MFA)? Types and Benefits
Risk-Based Authentication Software Glossary Terms
Risk-Based Authentication Software Discussions
I'm struggling with 1Password's secure sharing features. Can anyone explain the best way to use them?
Is LastPass app safe?
Looking for input from G2 reviewers and security architects, IT administrators, and helpdesk managers in the Risk-Based Authentication category, specifically from organisations where the false positive problem is the primary RBA implementation challenge.
The platforms with the strongest false positive avoidance evidence:
- Okta: The granular policy engine that allows security administrators to define different risk thresholds for different user populations, application sensitivity levels, and access scenarios is credited for tuning the risk model to the specific behaviour patterns of each organisation rather than applying a uniform sensitivity that produces false positives for the most common legitimate access patterns.
- Ping Identity: The continuous risk assessment model that re-evaluates authentication decisions as session context changes rather than making a single login-time determination is described as the false positive reduction mechanism for enterprise environments where legitimate user behaviour varies significantly, such as executives who travel internationally, remote workers who use different networks and devices across locations, and privileged users whose access patterns differ from standard employees.
- Microsoft Entra ID: The named location and compliant device exemptions in conditional access policies are the false positive reduction mechanisms most specifically credited by administrators managing Microsoft-centric environments. Defining trusted IP ranges, compliant device states, and hybrid joined device conditions as low-risk factors reduces the frequency with which the risk engine challenges users who are accessing from known, managed environments.
- Cisco Duo: The trusted device registration model, where users self-enroll their regularly used devices and the platform applies reduced friction for subsequent logins from those devices, is described as the false positive reduction mechanism that most directly improves the day-to-day user experience for legitimate users.
- RSA SecurID: The risk-based engine that combines user behaviour analysis, device attributes, and contextual signals to produce a risk score before each authentication event, with configurable thresholds that determine when step-up authentication is required, is described as the false positive reduction model for enterprise security teams that need predictable, auditable authentication behaviour.
For security architects and helpdesk managers who have tuned a risk-based authentication deployment to reduce false positives: what was the specific false positive scenario, such as remote workers on home networks, travelling executives, or users with multiple devices, that caused the most helpdesk contact initially, and what policy configuration change reduced it most effectively?
I’d track helpdesk tickets by false-positive scenario before and after policy tuning. Travel, new devices, VPN changes, and legitimate location shifts can look risky for very different reasons. The better RBA setup is probably the one that lets teams reduce those recurring challenges without broadly lowering thresholds and weakening protection for genuinely unusual access.



