What is KBA? Multiple Word Answers

8-4 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

8.7 Enabling Policies

Ensure that KBA security policies that pertain to your business and security needs are loaded on your system. Link them to a user group to which you want KBA to be enabled. For example, if you want the system to be able to challenge a user over the phone through a Customer Service Representative CSR, you must import and enable the System CC Challenge Policy. If you are using OAAM pre-package policies, enable phase 2 scenarios by adding the user group to which you want KBA to be enabled to Phase 2 pre- and post- authentication policies. Phase 2 provides optional registration scenarios that you may want to try out with users. If you find that the users like to use the registration process, you may add the scenarios to your authorization process. Phase 2 introduces much more user experience changes and includes the use of virtual authenticators for credential input. They are in charge of securely collecting the login details, and facilitating registrationchallenge. To enable Phase 2 scenarios 1. Ensure that Active has been chosen for the status of the policy. Refer to Section 10.11, ActivateDisable Policies. 2. Ensure that all the rules in the policy are active. Refer to Section 10.23, ActivateDisable Rule. 3. Ensure that the user group to which you want KBA to be enabled has been selected for the Run Mode option. Refer to Section 10.9.1, Linking a Policy to a Group. Note that it is important to ensure that the phase you are in corresponds to the policies you have your users linked to within OAAM Admin.

8.8 Configuring Rules for Policies

Change the rules within the registration and challenge policies with appropriate actions. For example, assign a challenge action as one of the actions you want triggered. For information, refer to Section 10.12.5, Specifying Results for the Rule.

8.9 Configuring the Challenge Question Answer Validation

Validations are used to validate the answers given by a user at the time of registration. For answers, you can restrict the users to alphanumeric and a few specific special characters by adding a Regex validation. For information, see Section 7.6, Setting Up Validations for Answer Registration. Note: If you have a policy customized, ensure that you do not import that policy again. Doing so breaks the policy that you had customized.