I have implemented google repatcha enterprise with the the score based assessment on on a register page. At first on a test website.
Now I wonder what would be a non fraudulent score. If I use my email address I get a score of 0.89. Would it be ok if I assess all scores >= 0.7 as non-fraudulent? What would be a good starting point as a minimum score?
I could log the scores and then compare the values over time. So I may could see what is a good minimum score.
On the recaptcha enterprise website it states: "With low scores, require MFA or email verification to prevent credential stuffing attacks." Where could I set up MFA or email verification? Is there a documentation about it?
Thank you for any recommendations.