Navigating to the Rules Search Page Searching for Rules

Managing Policies, Rules, and Conditions 10-31

3. Click the rule name in the Search Results table to open its Rule Details page in a

new tab. The Rule Details page provides tabs to the Summary, Preconditions, Conditions, and Results page. The total number of conditions in the rule appears in parenthesis next to the Conditions tab title. 4. Edit the rules general information Section 10.21.1, Modifying the Rules General Information . 5. Edit the Preconditions Section 10.21.2, Specifying Preconditions . 6. EditAdd Conditions Section 10.27, Adding Conditions to a Rule . 7. Edit the Results Section 10.21.3, Specifying the Results for a Rule .

8. Click Apply to save the changes or Revert to discard them.

10.21.1 Modifying the Rules General Information

From the Summary tab, you can modify the rule name, status, and description. 10-32 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Figure 10–15 Rule Details Summary Tab The fields displayed are listed in Table 10–9 .

10.21.2 Specifying Preconditions

From the Preconditions tab, you can specify the group to exclude and the geolocation confidence factor parameters. All preconditions filter whether or not a rule evaluates. The conditions do not process the rule if the preconditions are not met. The process stops at the preconditions level. Table 10–9 Rule Details Summary Tab Field Description Rule Name Name of the rule Policy Name Name of the policy. Read-only Status Status of the rule: Active or Disabled. If the rule status is changed from Active to Disabled, the rule is disabled and cannot be added to a policy. A policy that already contains the rule is not affected and continues to function as before. Description Description for the policy. Managing Policies, Rules, and Conditions 10-33 To specify preconditions for the rule:

1. Navigate to the Rule Details page.

a. In the Navigation tree, select Rules. The Rules Search page is displayed.

b. Search for the rule in which you want to specify preconditions for.

c. In the Search Results table, click the name of the rule. The Rule Details page

for that rule is displayed.

2. In the Rule Details page, click the Preconditions tab.

3. Excluded User Group

: In the Excluded User Group field, select the User ID group you do not want the policy to applied to.

4. Device Risk Gradient

: Device fingerprinting is a mechanism to recognize the device a customer typically uses to log in. Identification is based on combinations of the Device ID attributes, secure cookie, flash object, user agent string, browser characteristics, device hardware configuration, network characteristics, geolocation and historical context. Different use cases and exceptions are taken into account and help to define the device risk gradient. The device risk gradient specifies the certainty of the device being identified. It is standard in almost all rules as a precondition. The score ranges to specify the amount of device identification risk are: ■ 400 and lower - low risk ■ 401-700 - moderate risk ■ 701 and higher - high risk For example, a device risk gradient of 0 is an exact match whereas a device gradient of 500 is a similar device, and a score of 1000 a different device.

5. Country Confidence Factor

, State Confidence Factor, and City Confidence Factor : The IP location vendor can assign a confidence level to each of the three elements: city, state, and country. This confidence factor is based on IP geolocation information. The higher the value, the higher the level of confidence from Quova that the mapping of the location is correct. If you want the rule you are creating to be dependent on IP location identification accuracy, specify the amount of geolocation accuracy with which you want to run the rule. For example, if the range is 60 to 100, you may specify for the rule to run only if the IP location is greater than 60 positive.

10.21.3 Specifying the Results for a Rule

Results are the responses, such as the activation of an action and message, when a rule is triggered. For example, action event activated and alert message activated. As part of the process, specify: ■ Rule score and weight value ■ Actions ■ Alerts To specify the results for if the rule triggers, follow these steps: