Tom navigates to fingerprint details and finds that jsmith has logged in from the

6-78 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

2. Click the Fingerprint Data tab.

3. In the Search Results table, check to see if Spanish is listed as the Locale for the Fingerprint.

6.16.11 Use Case: Adding Devices Used for Fraud from a Location To a Risky Group

An investigator is viewing a table of devices used from a location and decides two of them were used for fraud. He can select them and add them to a high risk devices group to be used in future risk evaluations. He should not lose the context of what he was doing in the process. 1. Open the OAAM Admin Console. 2. Search for sessions. 3. Open location details page. 4. Search for devices used from this location. 5. Select two devices and add them to a high risk group.

6.16.12 Use Case: Adding Suspicious Device to High Risk Device Group

George is a user who gets blocked because he was logging in using a device that had been blocked more than three times in the last 24 hours. Jeff, an investigator wants to compare the blocked device with other devices this user has used in the past. He opens the fingerprint details for the blocked device and for another device the user has used many times successfully. From the user interface Jeff can see that the blocked device was a Linux machine with Opera running in Russian locale. The device the user seems to use most of the time is a Windows XP machine with IE running in English locale. As a result Jeff adds the blocked device to a high risk devices group, and adds the IPs used by the device to a high risk IPs group directly from the search screen. 1. Open the OAAM Admin Console. 2. Search for sessions. 3. Open 2 device details pages. 4. View the full list of fingerprint data for both devices. 5. Select device and add it to a high risk group. 6. Select IP and add it to a high risk group.

6.16.13 Use Case: Mark Devices and IPs as High Risk

An investigator is searching for sessions with high alerts in the last hour. Out of the 30 sessions he thinks two were fraud so he wants to mark the devices and IPs used as high risk. 1. Open the OAAM Admin Console. 2. Search for sessions with high alerts in the last hour. 3. Select the two sessions and click the add to group button. A dialog appears asking what data types from these sessions to add. 4. Select devices and IPs. Message appears which asks the user to select a device group and an IPs group. 5. Select and add the high risk devices and high risk IPs.