Setting Up KBA Setting Up KBA Overview

7-12 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager A page appears asking you to answer a security question. The question appears in QuestionPad. You are asked a challenge question because the public IP group and uncommon state rules are triggered. The public IP group rule contains the Location: in IP group condition and the uncommon state rule contains the User: state first time for user condition.

2. Enter the answer to the security question in QuestionPad and press Enter.

If you answer the question successfully, you are logged in.

7.3 Setting Up the System to Use Challenge Questions

This section provides a summary of the steps you must take to set up your system to use challenge questions. For information on performing a phased rollout KBA and enabling challenge questions, see Chapter 8, Enabling Challenge Questions.

7.3.1 Ensure Policies are Available

A full snapshot of policies, dependent components and configurations is shipped with Oracle Adaptive Access Manager. The snapshot is in the oaam_base_snapshot.zip file and located in the MW_HOMEIDM_ORACLE_HOMEoaaminit directory. If you are using pre-packaged policies, ensure that the OAAM snapshot has been imported. If you are not using pre-packaged policies, use this chapter as a guideline for enabling challenge questions. To import the snapshot, refer to the instructions in Section 2.6, Importing the OAAM Snapshot.

7.3.2 Ensuring that KBA PropertiesDefault Properties are Set

Ensure that the bharosa.kba.active property is set to true. See Chapter 28, Using the Properties Editor for information on modifying properties.

7.3.3 Ensure Challenge Questions are Available

The challenge questions must be present in Oracle Adaptive Access Manager before the users can be asked to register. Challenge questions are included in the OAAM snapshot. For information on importing the snapshot which contains the questions, see Section 2.6, Importing the OAAM Snapshot. If you are need to use challenge questions in languages other than English, import the appropriate oaam_kba_questions_locale.zip files from the MW_HOMEIDM_ORACLE_ HOMEoaamkba_questions directory. The locale identifier locale specifies the language version. Task [ ] Import the OAAM Snapshot [ ] Link the appropriate policies to the user group that you want KBA to be enabled for. [ ] Ensure that KBA properties are set [ ] Enable policies for your security and business needs [ ] Managing Knowledge-Based Authentication 7-13

7.3.4 Enabling Policies

Link policies that pertain to your business and security needs to a user group to which you want KBA to be enabled. For information on importing policies, see Chapter 10, Managing Policies, Rules, and Conditions.

7.4 Accessing Configurations in KBA Administration

This section describes how to navigate to KBA administration tasks in OAAM Admin. You can navigate to KBA tasks through the Navigation tree. The KBA Infrastructure provides you with access to all questions, validations, categories, registration and Answer Logic, and other elements. These are the subnodes under KBA, which provide access to the configurations in the KBA infrastructure: ■ Questions : For managing the tasks that impact challenge questions, such as creating new questions; activating, disabling, and editing questions; and importing questions that belong to a category not currently in the system. Double-click Questions to open the Questions Search page. ■ Validations : For managing the validation for the answers given by a user at the time of registration, such as creating validations based on the available validation schemes in the system, editing existing validations, and importing and exporting validations. Double-click Validations to open the Validations Search and Edit page. ■ Categories : For managing the question categories in the system. Double-click Categories to open the Categories Search page. ■ Registration Logic : For managing the level of logic algorithm used for the registration for challenge questions and answers. Double-click Registration Logic to open the Registration Logic configuration page. ■ Answer Logic : For managing the level of logic algorithm used for answer validation. Double-click Answer Logic to open the Answer Logic configuration page. For alternative methods to open search pages, refer to Section 3.9, Search, Create, and Import. Validation Search and Edit, Registration Logic and Answer Logic pages can be opened in the same manner as the search pages. Note that you cannot open the KBA node.

7.5 Managing Challenge Questions

The KBA functionality enables you to manage challenge questions. You can perform the following task for challenge questions: ■ Searching for a Challenge Question ■ Viewing Question Details and Statistics ■ Creating a New Question ■ Creating a Question Like Another Question