Answer Logic Introduction and Concepts

7-8 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

7.1.11.1 Reset Challenge Questions

The CSR resets a users challenge questions. The system deletes the existing questions and answers and generates a new question set for the user to register from. Registration of challenge questions is required at the next log in to the Web site.

7.1.11.2 Reset Challenge Questions and the Set of Questions to Choose From

The CSR resets the users challenge question set challenge questions and the set of questions to register from. Registration of challenge questions is required at the next log in to the Web site.

7.1.11.3 Increment User to the Next Question

The CSR resets the users next question so the system advances the user to the next challenge question in the list of registered questions. So if the user is currently being asked question A, question B or C is now asked. A different challenge question is presented at the next log in to the Web site.

7.1.11.4 Unlock a User

When the CSR unlocks the user that has been locked out of the system because of failed challenge questions. Unlocking the user resets the users failure counter.

7.1.11.5 Ask Question KBA Phone Challenge

The CSR uses the users challenge questions for phone authentication and enters users response. If the user answers the question correctly, the question failure counter and increment question counter are reset. The system automatically takes appropriate action depending on the status such as unlocking the user. Information about phone and online failures is provided in Section 7.1.10, Failure Counters. High level flows for the Ask Question action is presented in Chapter 4, Managing and Supporting CSR Cases. The matrix in Section 7.1.10, Failure Counters contains detailed examples for individual flows.

7.1.12 Disable Question and Category Logic

This section describes the logic to handle disabled questions and categories. Disabling Logic The disabling logic is as follows for KBA: ■ If you disable the last remaining question in a category, the category is automatically disabled as well. ■ The number of active categories must be equal to or greater than the maximum number of categories in the question menu. An error message results when you try to disable a category and this requirement is not met. Consequences The following table summarizes the disable results. Managing Knowledge-Based Authentication 7-9

7.1.13 Locked Status

Locked is the status that OAAM Admin sets if the user fails the question challenge. The Locked status is only used if the KBA or OTP Anywhere is in use. A user is locked out of the session after the failure counter reaches the maximum number of failures. After the user is locked out, a Customer Service Representative must reset the status to Unlocked before the account can be used to enter the system.

7.2 Setting Up KBA Overview

This section outlines the steps to manage the library, registration and answer processing of the challenge questions.

7.2.1 Loading Challenge Questions

The challenge questions must be loaded into Oracle Adaptive Access Manager before the users can be asked to register. For information on loading challenge questions, see Section 2.6, Importing the OAAM Snapshot.

7.2.2 Setting Up KBA

To set up KBA: ■ Create Category If the out-of-the-box categories do not meet your needs, create categories that can hold relevant questions you plan to create. For information, see Section 7.7.2, Creating a New Category. ■ Create Questions Create questions that can be applicable to the users accessing your application. For information, see Section 7.5.3, Creating a New Question and Section 7.13.2, Guidelines for Designing Challenge Questions. ■ Apply Validations