FeatureReleased 8 May 2026
Stronger login and session security
A round of hardening to how sign-in and sessions work: a check against known breached credentials at login, admins can sign a user out everywhere, password changes end other sessions, and a cleaner experience when a session expires.
What changed
Security
- At login, credentials are checked against known breach datasets. A high-confidence match without MFA blocks the login and prompts a password reset; otherwise the login succeeds with a warning.
- Admins can force a user to log out of all devices, optionally requiring a password change on next login.
- Changing or resetting a password ends other sessions: a forgotten-password reset ends them all, a profile change ends all but the current one.
Improved
- A cleaner experience when a session expires: a redirect to login with a clear message, mid-edit context kept in a modal, SSO re-authentication without re-entering the email, and a return to the page afterwards.