Investigation and the Importance of Details Pages

6-16 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Figure 6–10 Location Details: Users You can also look at all the different alerts that were generated from the logins or sessions that occurred from the United States by using the Alerts tab of the Location Details page to search on the Alert ID, Alert Type, or Alert Level. Figure 6–11 Location Details: Alert Viewing Additional Details for Investigation 6-17

6.10 Viewing Alerts

When an alert is generated it is associated with the user, device, and location that has taken part in the authentication. The login session holds information about the alert. Any changes to the alert type or alert message are automatically reflected in the alerts page. It shows the new information. Other than the Alerts tab, the detail pages display alert instances based on the leveltype at the time they were triggered. Alert instances are grouped with the alert template they belong to. For example, if there were 10 sessions with alert level High last month and then the Administrator changed the level of that template to low, then the next 10 instances are displayed with the level Low.

6.11 User Details Page

The User Details page provides general details about the user and cross reference on other data types such as device, location, alerts, browser, OS, and so on. Also shown are details related to the user such as unique ID, Organization ID, groups the user belongs to, sessions and cache data, fingerprint, browser, OS, locale, and so on. You can open a User Details page to view details regarding that user by clicking the User Name or UserID link from the Sessions search, Session Details, and other pages. Figure 6–12 shows a User Details page. Figure 6–12 User Details: Summary The User Details page is divided into the following tabs: 6-18 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Detailed information about the User Details tabs follow.

6.11.1 User Details: Summary Tab

The Summary tab contains basic, registration, and profile information for the user. General Information Table 6–9 summarizes the basic information about a user that is provided by the User Details: Summary Tab. Registration Information The first time a user logs in, he must go through the registration process. Information is capture during the process. Table 6–10 summarizes the properties and attribute values that identify the status of each action performed by the user during the registration process. Table 6–8 User Details Tabs User Details Tab Function Summary The Summary tab contains basic, registration, and profile information for the user. Groups The Groups tab shows a listing of the user groups that the user is a member of. The user can belong to User ID and User Name groups. Locations The Locations tab lists successful and unsuccessful login attempts from all user locations. This tab enables you to find out which locations and how many times a user logged in from a particular location. Devices The Devices tab lists all the devices that have been used in a session by the user during the time frame mentioned in the search criteria. It lists both successful and unsuccessful login attempts from all users devices. This tab helps you find out which devices and how many times a device was used by the user. Alerts The Alerts tab lists alerts that are triggered and generated for a user by the application during the transaction process. The information shown is based on alert templates and not alert instances. Alert templates are displayed with the current details leveltype. Sessions The Sessions tab lists login sessions for a user for a particular period. Policies The Policies tab lists default and custom rules that are run for a user by the rules engine based on the checkpoints during authentication. Fingerprint Details The Fingerprint Details tab lists fingerprints created for the user during login. Table 6–9 User Details: Basic Information about the User Field Definition User Name Login name given by user to login. User ID Unique Identifier of that device Organization ID Identifies the organization to which the user belongs. Valid User True if the user has authenticated successfully at least once. Created Date Date on which the user was created. Also, this refers to the first login date of the user. Viewing Additional Details for Investigation 6-19 Profile Data This Profile Data section lists important statistics about the user using cached data. Aggregate values are shown for User Groups, Action Counter Data, Action Override Data, Fingerprint Data, and Policies. These values use cache data and records are always shown even if the database is purged. Figure 6–13 Profile Data Table 6–10 User Details: Registration Information Field Definition Completed Registration YesNo Identifies whether user has completed the registration process like registered challenge questions, image and phrase, which are unique for each user and used for identifying a user for security reasons. Virtual Device Type List of device IDs that the user registered as secure device during registration process. Maximum of three devices can be registered. Personalization Active YesNo Identifies whether user registered Image and Phrase. Question Active YesNo Identifies whether user registered Challenge Questions. OTP Active YesNo Identifies whether user has been assigned One Time Password on SMSEmail Challenge. Last Online Action The last online action performed by user in his most recent transaction. Date of Last Online Action Date of last online action performed by user in his most recent transaction. Temporary Allow YesNo Identifies whether the user was blocked and is allowed to access his account temporarily.