MFA settings now complete reliably, verification attempts are bounded, and customer MongoDB connections require verified TLS while rejecting private-network destinations at connection time.
MFA reliability
Authenticator and email MFA changes now return an accurate success response only after the account state is complete. Recovery-code replacement is operational again, email verification codes use cryptographic randomness and encrypted storage, and repeated verification attempts are bounded.
Customer-owned storage boundary
Business Chat, IdentChat and Network self-managed MongoDB connections require certificate-verified TLS. Both the initial validation and the database driver's connection-time DNS lookup reject loopback, private, mapped IPv4, multicast and other non-public destinations.