Click OK to upload PreAuth_Block_policy.zip.

10-46 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager To copy a rule: 1. Log in to OAAM Admin as an administrator.

2. In the Navigation tree, double-click Rules. The Rules Search page is displayed.

3. In Search filter, search for: ■ Rule Name: Blacklisted device rule ■ Checkpoint: Post-Authentication 4. Click Search. The System -Post Blocking policy contains the Blacklisted devices rule.

5. In the Search Results table, click Blacklisted devices in the Rule Name column.

6. In the Rules Details page for that rule, click the Copy Rule button. The Copy Rule

screen is displayed.

7. For Policy, select System - Pre Blocking as the pre-authentication policy you want

to copy the rule to.

8. For Rule Name, keep Blacklisted devices or enter a new name for the rule that

you are copying.

9. For Description, keep This rule triggers if the device used has been blacklisted

in the past or enter a new description.

10. Click OK to copy the rule to the pre-authentication policy, System - Pre Blocking.

A confirmation dialog appears with the message, Rule has been copied successfully.

11. Click OK to dismiss the dialog.

12. Navigate to the Rules Search page and check in the Search Results table to verify

that the Blacklisted device rule appears in the System - Pre Blocking policy. 13. Navigate to the Policies Search page and search for the System -Post Blocking policy.

14. Click System -Post Blocking in the Search Results table.

15. In the Policy Details page, click the Rules tab.

16. In the Rules tab, select Blacklisted devices and click Delete.

A screen appears asking, Are you sure you want to delete the selected rules? The Blacklisted devices rule is listed in the screen.

17. Click Yes.

Another confirmation appears with the message, Selected rules are deleted successfully.

18. Click OK to dismiss the dialog.

10.34.7 Use Case: Trigger Combination

To KBA challenge a user Oracle Adaptive Access Manager must check two things: ■ First, check to see whether the user has challenge questions registered. ■ Second, if the user has a questions set active challenge him if a challenge scenario has to be performed.