# Which risk-based authentication platforms are most reliable for avoiding false positive lockouts based on user reviews?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Looking for input from G2 reviewers and security architects, IT administrators, and helpdesk managers in the <a class="a a--md" elv="true" href="https://www.g2.com/categories/risk-based-authentication-rba">Risk-Based Authentication category</a>, specifically from organisations where the false positive problem is the primary RBA implementation challenge.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">The platforms with the strongest false positive avoidance evidence:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/okta/reviews"><strong>Okta</strong></a>: The granular policy engine that allows security administrators to define different risk thresholds for different user populations, application sensitivity levels, and access scenarios is credited for tuning the risk model to the specific behaviour patterns of each organisation rather than applying a uniform sensitivity that produces false positives for the most common legitimate access patterns. </li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/ping-identity/reviews"><strong>Ping Identity</strong></a>: The continuous risk assessment model that re-evaluates authentication decisions as session context changes rather than making a single login-time determination is described as the false positive reduction mechanism for enterprise environments where legitimate user behaviour varies significantly, such as executives who travel internationally, remote workers who use different networks and devices across locations, and privileged users whose access patterns differ from standard employees. </li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-entra-id/reviews"><strong>Microsoft Entra ID</strong></a>: The named location and compliant device exemptions in conditional access policies are the false positive reduction mechanisms most specifically credited by administrators managing Microsoft-centric environments. Defining trusted IP ranges, compliant device states, and hybrid joined device conditions as low-risk factors reduces the frequency with which the risk engine challenges users who are accessing from known, managed environments.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cisco-duo/reviews"><strong>Cisco Duo</strong></a>: The trusted device registration model, where users self-enroll their regularly used devices and the platform applies reduced friction for subsequent logins from those devices, is described as the false positive reduction mechanism that most directly improves the day-to-day user experience for legitimate users.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/rsa-securid/reviews"><strong>RSA SecurID</strong></a>: The risk-based engine that combines user behaviour analysis, device attributes, and contextual signals to produce a risk score before each authentication event, with configurable thresholds that determine when step-up authentication is required, is described as the false positive reduction model for enterprise security teams that need predictable, auditable authentication behaviour.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For security architects and helpdesk managers who have tuned a risk-based authentication deployment to reduce false positives: what was the specific false positive scenario, such as remote workers on home networks, travelling executives, or users with multiple devices, that caused the most helpdesk contact initially, and what policy configuration change reduced it most effectively?</p>

##### Post Metadata
- Posted at: about 10 hours ago
- Author title: Marketing Executive
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;I’d track helpdesk tickets by false-positive scenario before and after policy tuning. Travel, new devices, VPN changes, and legitimate location shifts can look risky for very different reasons. The better RBA setup is probably the one that lets teams reduce those recurring challenges without broadly lowering thresholds and weakening protection for genuinely unusual access.&lt;/p&gt;

##### Comment Metadata
- Posted at: about 6 hours ago
- Author title: Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


