Forgot Password Flow Reset Password KBA-Challenge Flow

11-6 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

11.5.1.1.4 Trigger Combinations

None

11.5.2 Authentication Pad Policies

The Authentication Pad policy is summarized in this section.

11.5.2.1 OAAM AuthenticationPad

This policy determines the OAAM Authentication Pad to use.

11.5.2.1.1 OAAM AuthenticationPad Policy Summary

Table 11–3 OAAM Pre-Authentication Policy Rules Details Rule Rule Condition and Parameters Results Blacklisted Countries Location: In Country group Is In List = TRUE Country in country Group=OAAM Restricted Countries Action = OAAM Block Alert = OAAM Restricted Country Score = 1000 Weight = 100 Blacklisted devices Device: Device in group Is in group = TRUE Device in group = OAAM Restricted Devices Action = OAAM Block Alert = OAAM Restricted Device Score = 1000 Weight = 100 WEBZIP used Device: Browser header substring Substring to check = WEBZIP Action = OAAM Block Alert = OAAM Restricted Software Score =1000 Weight = 100 Blacklisted IPs Location: IP in group Is in List = TRUE IP List = OAAM Restricted IPs Action = OAAM Block Alert = OAAM Restricted IP Score = 1000 Weight = 100 Blacklisted ISPs Location: ISP in group Is in List = TRUE ISP List = OAAM Restricted ISPs Action = OAAM Block Alert = OAAM Restricted ISP Score = 1000 Weight = 100 Blacklisted users User: In Group Is in group = TRUE User Group = OAAM Restricted Users Action = OAAM Block Alert = OAAM Restricted User Score = 1000 Weight = 100 Table 11–4 OAAM AuthenticationPad Policy Summary Summary Details Purpose Determines which OAAM Authentication Pad to use. OAAM Security and Autolearning Policies 11-7

11.5.2.1.2 OAAM AuthenticationPad Flow Diagram

Figure 11–5 OAAM AuthenticationPad Flow

11.5.2.1.3 OAAM AuthenticationPad: Details of Rules

The table below shows the rule conditions and parameters in the OAAM AuthenticationPad Policy. Scoring Engine Average Weight 100 Group Linking All Users Table 11–4 Cont. OAAM AuthenticationPad Policy Summary Summary Details 11-8 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

11.5.2.1.4 OAAM AuthenticationPad: Trigger Combinations

Table 11–5 OAAM Authentication Pad Policy Rules Details Rule Rule Condition and Parameters Results Challenge SMS Session: Check value in comma separated values Parameter Key = AvailableChallengeTypes Value to Check = ChallengeSMS Return if in list = TRUE Action = OAAM Text Pad Alert = NONE Score = 0 Registered Image and Caption User: Authentication Image Assigned Is Assigned = TRUE Action = OAAM Personalized Pad Alert = NONE Score = 0 Key Pad User User: Authentication Mode Authentication Mode is = Full Keypad Action = OAAM KeyPad Alert = NONE Score = 0 Challenge Email Session: Check value in comma separated values Parameter Key = AvailableChallengeTypes Value to Check = ChallengeEmail Return if in list = TRUE Action = OAAM Text Pad Alert = NONE Score = 0 Register Challenge Question Session: Check value in comma separated values Parameter Key = AvailableChallengeTypes Value to Check = RegisterChallengeQuestion Return if in list = TRUE Action = OAAM Question Pad Alert = NONE Score = 0 Check if mobile browser is used DEVICE: Check if device is using Mobile Browser Mobile Browsers Group = OAAM Mobile Browsers Group Default Return Value = FALSE Action = NONE Alert =OAAM Mobile Users Score = 0 Challenge Question Session: Check value in comma separated values Parameter Key = AvailableChallengeTypes Value to Check = ChallengeQuestion Return if in list = TRUE Action = OAAM Question Pad Alert = NONE Score = 0