Editing Conditions Configure the UMS Driver

Managing Policies, Rules, and Conditions 10-43 d. Modify the policy status, scoring engine, and weight according to your requirements. By default, the policy status is Active. A policy that is disabled is not enforced at the checkpoint. For more information on the Scoring Engine, see Chapter 14, Using the Scoring Engine.

e. Click Apply.

A confirmation dialog displays the status of the operation. If you click Apply and the required fields are not filled in an error message is displayed.

f. Click OK to dismiss the confirmation dialog.

5. Configure the policy to run for all users.

a. Click the Group Linking tab.

b. For Run Mode, select All Users.

Since All Users is selected for the run mode, the policy is executed run for all users. Specifying a run mode is a mandatory step in order for the policy to execute. It enables the policy to executerun for a set of users or all users. For information, see Section 10.9, Linking Policy to All Users or a User ID Group.

c. Click Apply.

A confirmation dialog displays the status of the operation.

d. Click OK to dismiss the confirmation dialog.

If the KBA Challenge policy was created successfully, it would be listed in the Search Results table of the Policies Search page. Although not covered in this use case, for the policy to function, you must add a rule to the policy either by creating a new rule within a policy Section 10.12, Adding a New Rule or by copying an existing one Section 10.15, Copying a Rule to a Policy to the policy.

10.34.4 Use Case: Add New Rule

After you have created a security policy see Section 10.34.3, Use Case: Create a Policy. you are ready to create a new rule to perform the risk evaluation in your use case. The use case requires an evaluation of the physical distance between the location a user is logging in from now verses the last location he came from. This rule calculates the velocityspeed required to travel between the location given the time. The security team has determined that if the user appears to travel faster then 500 miles per hour between location and the device used is different then the user should be given a KBA challenge. Directions: Create a new rule, User Velocity and use the out-of-the-box condition, User: Velocity from last successful login. To add a new rule: 1. Log in to OAAM Admin as an administrator.

2. In the Navigation tree, double-click Policies. The Policies Search page is

displayed. 3. Search for KBA Challenge. 10-44 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

4. In the Search Results table, click KBA Challenge. The Policy Details page for

KBA Challenge is displayed.

5. In the Policy Details page, click the Rules tab.

6. In the Rules tab, click Add to add a new rule.

The New Rule page is displayed.

7. Enter User Velocity as the rule name.

8. Enter a description for the rule. 9. Select the rule status. When the New Rule page first appears, the default value for the rule status is Active .

10. Add the User: Velocity from last successful login rule condition to create the new

rule.

a. To add the User: Velocity from last successful login condition, click the

Conditions tab.

b. In the Conditions tab, click Add. The Add Condition page appears.

c. Search for the User: Velocity from last successful login condition by entering

velocity in the Condition Name field and then clicking Search.

d. In the Results table, select that condition and click OK.

e. In the New RuleUser Velocity page, select User: Velocity from last

successful login in the top panel. The bottom panel displays the parameters of the condition. f. In the bottom panel, modify the parameters.

a. Enter 500 for Miles per Hour is more than.

b. Select true for Ignore if last login device is same.

g. Click Save to save your changes. A confirmation dialog appears with a

message that the modified rule parameters were saved successfully.

h. Click OK to dismiss the confirmation dialog.

11. Add a KBA challenge as a result of the User Velocity rule.

a. Click the Results tab.

The Results tab enables you to specify the results for the rule if the conditions are met. b. To set up a KBA challenge to occur if the rule is triggered, select ChallengeQuestionPad in the Actions Group list. 12. Click Apply. A confirmation dialog appears with a message that the modified rule details were saved successfully. If the required fields are not filled in and the user clicks Apply, an error is displayed. If the rule was successfully created, the new rule should be listed in the Rules tab of the Policy Details page.