In the Search Results table, click Blacklisted countries. The Rule Details page for

Managing Policies, Rules, and Conditions 10-49 15. Select compare operator as for each state.

16. Click Next.

17. Create Rule1: Add pattern condition, Entity is member of bucket less than some

percentage of times . Select Pattern 1 and percentage = 10 and select 1 month as time period.

18. Add condition to rule, User: Question status to check if he has registered

questions.

19. Add action, KBA Challenge to Rule 1. This rule triggers if the user has

registered questions and he has logged in from time bucket less than 10 of time. The Result, he is challenged with KBA.

20. Create Rule 2: Add pattern condition, Entity is member of bucket less than some

percentage of times . Select Pattern 2, percentage =20 and select 15 days as time period

21. Create Rule 3: Add pattern condition, User: Is OTP enabled. Using condition

Challenge Channel Status 22. Create a policy and add all three rules. 23. Add trigger combination to policy such that if all rules are triggering true then action is Challenge OTP. For more information on patterns, see Chapter 17, Managing Autolearning.

10.34.9 Use Case: Configuring User Flow

Jeff a Security Administrator has a brand new installation and must import the base security policies into the development environment of the Oracle Adaptive Access Manager Server. To support the base policies he also configures a black-listed country group. As well he links user groups to the proper roll-out phase policies to test phase two for a group of test users. To import a policy: 1. Log in to OAAM Admin as an administrator.

2. In the Navigation tree, double-click Policies. The Policies Search page is

displayed.

3. Click Import Policy in the Policies Search page. The Import Policy screen is

displayed.

4. Click Browse and search for oaam_sample_policies_for_uio_integration.zip.

5. Click OK to upload oaam_sample_policies_for_uio_integration.zip.

A confirmation dialog displays the status of the operation. The imported policies are listed in the Imported List section. An error is displayed if you try to import files in an invalid forma or an empty ZIP file.

6. Click OK to dismiss the confirmation dialog.

7. In the Policy Search page, verify that the policy appears in the Search Results

table.

8. In the Navigation tree, double-click Groups. The Groups Search page is

displayed.