Search for the Location: IP in Group condition by entering IP in the In the Search Results table, select that condition and click OK. Authentication Flow

11 OAAM Security and Autolearning Policies 11-1 11 OAAM Security and Autolearning Policies This chapter describes the flows for the main scenarios in authentication and the policies and rules that are shipped with the product as part of the OAAM base snapshot. This chapter also includes autolearning policies that are shipped out of the box. Policies are also included as separate policy files to import but they require that you import questions, entities, and patterns, and set up autolearning related properties.

11.1 Authentication Flow

Figure 11–1 shows the authentication flow of OAAM server when a user logs in to an application that is protected by Oracle Adaptive Access Manager. 11-2 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Figure 11–1 Authentication Flow

11.2 Forgot Password Flow

The Forgot Password flow allows the users to reset their password after successfully answering all challenge questions. OAAM Security and Autolearning Policies 11-3 Figure 11–2 Forgot Password Flow

11.3 Reset Password KBA-Challenge Flow

Challenge Reset enables users to reset their challenge registration. 11-4 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager Figure 11–3 Reset Password

11.4 OAAM Checkpoints and Responsibilities

The following table lists the OAAM checkpoints and their responsibilities.

11.5 Out-of-the-Box OAAM Policies

OAAM comes standard with out-of-the-box policies pre-built to detect suspicious activity. Table 11–1 OAAM Checkpoints and Responsibilities CheckPoint Name Responsibilities Pre-Authentication Determine if the request has to be BLOCKED Device Identification Determine how to identify the device AuthentiPad Determine which authentication pad to use Post Authentication Determine if the user has to be ALLOWED or BLOCKED Registration Determine which pieces of user information is pending registration Challenge Determine which mechanism to use to challenge the user CSR KBA Challenge Applicable when customer calls in for service. Reset settings is performed through CSR KBA Challenge. Forgot Password Activity to reset password performed based on challenge Preferences Sets the user information Image, phrase, OTP settings, and so on OAAM Security and Autolearning Policies 11-5

11.5.1 Pre-Authentication Policies

Pre-authentication policies are summarized in this section.

11.5.1.1 OAAM Pre-Authentication

This policy stops fraudulent login attempts before the password is entered.

11.5.1.1.1 Policy Summary

11.5.1.1.2 OAAM Pre-Authentication Flow Diagram

Figure 11–4 OAAM Pre-Authentication Flow

11.5.1.1.3 OAAM Pre-Authentication: Details of Rules

The table below shows the rule conditions and parameters in the OAAM Pre-Authentication Policy. Table 11–2 OAAM Pre-Authentication Policy Summary Summary Details Purpose Stops fraudulent login attempts before the password is entered. Scoring Engine Maximum Weight 100 Group Linking All Users 11-6 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

11.5.1.1.4 Trigger Combinations

None

11.5.2 Authentication Pad Policies

The Authentication Pad policy is summarized in this section.

11.5.2.1 OAAM AuthenticationPad

This policy determines the OAAM Authentication Pad to use.

11.5.2.1.1 OAAM AuthenticationPad Policy Summary

Table 11–3 OAAM Pre-Authentication Policy Rules Details Rule Rule Condition and Parameters Results Blacklisted Countries Location: In Country group Is In List = TRUE Country in country Group=OAAM Restricted Countries Action = OAAM Block Alert = OAAM Restricted Country Score = 1000 Weight = 100 Blacklisted devices Device: Device in group Is in group = TRUE Device in group = OAAM Restricted Devices Action = OAAM Block Alert = OAAM Restricted Device Score = 1000 Weight = 100 WEBZIP used Device: Browser header substring Substring to check = WEBZIP Action = OAAM Block Alert = OAAM Restricted Software Score =1000 Weight = 100 Blacklisted IPs Location: IP in group Is in List = TRUE IP List = OAAM Restricted IPs Action = OAAM Block Alert = OAAM Restricted IP Score = 1000 Weight = 100 Blacklisted ISPs Location: ISP in group Is in List = TRUE ISP List = OAAM Restricted ISPs Action = OAAM Block Alert = OAAM Restricted ISP Score = 1000 Weight = 100 Blacklisted users User: In Group Is in group = TRUE User Group = OAAM Restricted Users Action = OAAM Block Alert = OAAM Restricted User Score = 1000 Weight = 100 Table 11–4 OAAM AuthenticationPad Policy Summary Summary Details Purpose Determines which OAAM Authentication Pad to use.