Part of: CIAMLast updated 19 August 2026 · 1 min read

What is adaptive access (risk-based authentication)?

Adaptive access adjusts authentication requirements based on contextual risk signals, such as an unfamiliar device, an unusual location, or an atypical time of access, rather than applying the same friction to every login. Low-risk sessions proceed with minimal friction, while higher-risk sessions trigger step-up verification such as an additional MFA challenge.

Frequently asked questions

What signals typically drive an adaptive access decision?

Common signals include device recognition, IP or location changes, time-of-day patterns, and known-bad indicators like breached credentials.

Does adaptive access replace MFA?

No, it decides when to require MFA (or a stronger factor), rather than replacing MFA itself.

Is this the same as fraud detection?

They're closely related and often work together, but fraud detection is broader; adaptive access is specifically about tuning authentication friction to risk. See fraud detection.

Building the integration, not choosing it?Definitions stop where implementation starts. The developer docs carry the API references, SDKs and SCIM endpoints.
Developer doc

Ready to move beyond legacy CIAM?

Definitions are the easy part. Go live in weeks with identity that governs AI agents, customers, and partners from one place.

Learn more