TrustPortDocs

How scoring works

For each user, Radar builds a picture of their normal sign-ins: the networks, devices and countries they use and the times of day they sign in. After five clean sign-ins it has enough to compare against. Each new attempt is scored on how far it strays from that picture.

SignalWhat Radar noticed
New networkFirst sign-in from this IP range
New deviceFirst sign-in from this device or browser
New countrySigning in from a country this person doesn’t usually use
Unusual timingAn hour or rhythm that doesn’t match their history
Failed attemptsWrong passwords, especially several in a row

Only clean, successful sign-ins teach Radar what normal looks like, so an attacker who does get in can't train it to accept them.

What each score means

ScoreLevelWhat happens
0–29LowSign-in continues.
30–59MediumSign-in continues; the score is recorded.
60–79HighSign-in continues, and it is flagged as high risk on the Radar page.
80–100CriticalSign-in is refused, even with the right password, and a LoginBlocked event is recorded.
Add a second factor for risky sign-ins
Pair Radar with an MFA step-up action to ask for an authenticator code when something looks off, instead of waiting for a score high enough to block.

Review activity

In the dashboardThreat Radar & Security

The Radar page shows the last 24 hours:

  • Logins scored, high-risk scores, blocked logins and the average score.
  • A feed of recent scores with the IP address and location, score, action taken and the reasons behind it.
  • Filters for high-risk and blocked attempts, and search by IP, location or reason.

When something looks wrong

  1. Open the person's recent events in the audit log.
  2. If you think the account is compromised, lock it from Users; every session ends at once.
  3. Ask the owner to reset their password and add two-factor authentication before you unlock it.
If Radar can't be reached, sign-ins continue without a score rather than failing. Radar never locks your users out on its own.
© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.