
MikeP.85680 (Customer) asked a question.
We have User Enumeration Prevention (UEP) enabled in our org, and it works as expected for the login and password reset flows. However, we've noticed a behavioral inconsistency in the self-service account unlock flow that appears to undermine UEP entirely.
Observed behavior
When a user submits the account unlock form:
1. Account exists: the form immediately pre-selects "Email" with no authenticator list shown.
2. Account does not exist: the form displays a list of available authenticators (email is the only option in our case, but it is presented as a selectable list item).
Expected behavior
The response should be identical regardless of whether the account exists - either always show the authenticator selection list, or always pre-select email. No observable difference should be present between the two states. This is exactly how it works for the Forgot Password scenario btw.
Questions
- Is there a configuration workaround to enforce consistent behavior for the unlock flow?
- Is this a known issue or an acknowledged gap in UEP coverage?

Hello @MikeP.85680 (Customer) Even though Password Reset and Account Unlock are governed by the exact same legacy policy settings, they use different underlying evaluation sequences in OIE:
Additionally, you can open a case with Support for an additional deep dive into this to see if maybe something else is missed.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.