Skip to content

The 14 Auth0 security checks Black Cat runs

Black Cat SSPM evaluates 14 security policies against your Auth0 configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.

audit

infoManagement API Change Event

Review successful Management API change events for unexpected configuration changes

authentication

highConnection Brute Force Protection Disabled

Enable brute-force protection on database connections

configuration

highDynamic Client Registration Enabled

Disable tenant-wide Dynamic Client Registration unless explicitly required

identity

mediumDormant User

Block or remove Auth0 accounts inactive for 90+ days

logging

lowNo Recent Audit Events

Confirm Auth0 tenant logs are being generated and retained

mfa

highUser Without MFA

Enroll Auth0 users in multi-factor authentication

highConnection MFA Disabled

Enable MFA on database connections

highTenant MFA Not Enforced

Enforce MFA at the tenant level via a Guardian policy

oauth

highApplication Risky Grant Type

Remove ROPC (password) and implicit grant types from applications

highPublic Client With Confidential Grant

Add client authentication to applications using confidential grants

mediumWildcard Callback URL

Replace wildcard and insecure callback/origin URLs with exact HTTPS URLs

password policy

mediumWeak Connection Password Policy

Raise the password policy on database connections to good or excellent

privilege

highRole Targets Management API

Review roles that grant write access to the Auth0 Management API

session

mediumLong Tenant Session Lifetime

Reduce the tenant session lifetime to 168 hours (7 days) or less

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial