I am receiving a number of failed logins, intermixed with normal/successful logins. The failed logins come in ‘bursts’ of 6-8 at a time, all within a few seconds of each other, and all with the same description: “Missing required parameter: response_type”
These failed logins also do not have an assigned Application or Connection - they all say “N/A”, whereas the successful logins all have their correct designations listed.
This feels a bit like a series of bot/spam login attempts, but am uncertain how to verify this or go about restricting them. Any advice would be appreciated.
I can guarantee that this is unrelated to bot/spam login attempts because it refers to a missing query parameter. If this were bot/spam activity, you would see scripted login/signup attacks, which you can workaround by enabling the features for Attack Protection.