FeatureReleased 8 May 2026

Stronger login and session security

A round of hardening to how sign-in and sessions work: a check against known breached credentials at login, admins can sign a user out everywhere, password changes end other sessions, and a cleaner experience when a session expires.

What changed

Security
  • At login, credentials are checked against known breach datasets. A high-confidence match without MFA blocks the login and prompts a password reset; otherwise the login succeeds with a warning.
  • Admins can force a user to log out of all devices, optionally requiring a password change on next login.
  • Changing or resetting a password ends other sessions: a forgotten-password reset ends them all, a profile change ends all but the current one.
Improved
  • A cleaner experience when a session expires: a redirect to login with a clear message, mid-edit context kept in a modal, SSO re-authentication without re-entering the email, and a return to the page afterwards.