Validations Failure Counters Introduction and Concepts

Managing Knowledge-Based Authentication 7-9

7.1.13 Locked Status

Locked is the status that OAAM Admin sets if the user fails the question challenge. The Locked status is only used if the KBA or OTP Anywhere is in use. A user is locked out of the session after the failure counter reaches the maximum number of failures. After the user is locked out, a Customer Service Representative must reset the status to Unlocked before the account can be used to enter the system.

7.2 Setting Up KBA Overview

This section outlines the steps to manage the library, registration and answer processing of the challenge questions.

7.2.1 Loading Challenge Questions

The challenge questions must be loaded into Oracle Adaptive Access Manager before the users can be asked to register. For information on loading challenge questions, see Section 2.6, Importing the OAAM Snapshot.

7.2.2 Setting Up KBA

To set up KBA: ■ Create Category If the out-of-the-box categories do not meet your needs, create categories that can hold relevant questions you plan to create. For information, see Section 7.7.2, Creating a New Category. ■ Create Questions Create questions that can be applicable to the users accessing your application. For information, see Section 7.5.3, Creating a New Question and Section 7.13.2, Guidelines for Designing Challenge Questions. ■ Apply Validations Table 7–1 Disable Results in Question and Category Logic Disable Question or Category New customers user with question in question set users with question registered Question The disabled question is not used to generate new users question sets. At re-registration or when a user changes his preference: Disabled question are replaced with another question from the same category. The disabled question continues to be active. If the user is re-registering or changing user preference, the disabled question is replaced with another question from the same category. Category The disabled category is not used to generate new users question sets. At re-registration or when a user changes his preference: All questions in the disabled category are replaced with questions from a new category that has not been used to generate current question set. Questions from the disabled category continue to be active. If the user is re-registering or changing user preference, all questions in the disabled category are replaced with questions from a new category that has not been used to generate the current question set. 7-10 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Apply validations to the questions. For information, see Section 7.6.2, Adding a New Validation.

7.2.3 Setting Up Challenge

To set up challenge: ■ Set up the Registration Logic - Validations are used to validate the answers given by a user at the time of registration. For information, see Section 7.8, Configuring the Registration Logic. ■ Set up the Answer Logic - The Answer Logic settings can be configured for the exactness required for challenge question answers and for answering thresholdtolerance, such as the level of fat fingering, typos, abbreviations, and so on. For information, see Section 7.9, Adjusting Answer Logic.

7.2.4 User Flow

The following diagram illustrates the user experience with the KBA framework implemented. Figure 7–2 KBA User Flow