You are here:
Best Practices and Additional Information for Anomalous Logins
Understanding the nature of anomalous logins and available resources can help you manage and respond to these events effectively.

Use more general search terms.
Select fewer filters to broaden your search.
Understanding the nature of anomalous logins and available resources can help you manage and respond to these events effectively.
| Available in both Salesforce Classic (not available in all orgs) and Lightning Experience. |
Available in: Enterprise, Unlimited, and Developer Editions Requires Salesforce Shield or Salesforce Event Monitoring add-on subscriptions. |
A login is considered anomalous when its characteristics (IP address, browser agent, location, etc.) significantly deviate from the user's established baseline of typical logins over the past 90 days. Machine learning models create a profile for each user based on their login history. Incoming logins are compared against this baseline, and an alert is triggered when a significant deviation exceeds a defined threshold. If no response is received for the email notification about this event, the system will assume it was a false positive, and the user will not receive the same notification for the same endpoint (IP, Browser, UserId combination) within a 30-day window.
Salesforce continuously monitors login activity for various suspicious patterns, including credential stuffing and brute-force attacks. Successful logins from suspicious clients trigger mitigating actions like identity challenges and forced password resets. Practicing good password hygiene, never sharing credentials, and enabling multi-factor authentication (MFA) are crucial steps to prevent unauthorized access.

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.