Android and iOS

Combining risk signals with authentication

OAuth, passkeys, biometrics, device registration and recovery.

Identity and sessions1 min readEditorial methods

Device and application risk can inform authentication. A signal does not prove malicious intent.

Evaluation approach

Consider confidence, age and transaction impact. Define additional evidence or limited-access options for uncertainty.

Application example

A high-value action from a new device may need a different policy from low-risk viewing on an established device.

Limits and considerations

One device label cannot explain all account behavior.

Handling uncertain signals

Missing evaluation is neither automatic safety nor automatic attack evidence. Choose step-up, restricted access or retry according to impact and record the reason.

Checks and decisions

  • Measure signal age
  • Classify operations
  • Monitor false positives

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.