Editing a Policys General Information

Managing Policies, Rules, and Conditions 10-19 To add general information about the rule, the procedure is as follows:

1. In the Summary tab, enter the name of the rule and a description. Duplicate rule

names are allowed across policies, but not within the same policy. If you try to navigate to one of the other tabs before entering a rule name or description, an error message reminds you that a value is required. The policy name cannot be changed.

2. If you want to disable the rule, select Disabled. Rule Status has the default value

of Active. A rule that is disabled is not run when the policy is enforced.

10.12.3 Configuring Preconditions

To configure preconditions for the rule, follow the procedure in Section 10.21.2, Specifying Preconditions. Through preconditions, you can specify the group to exclude and the geolocation confidence factor parameters.

10.12.4 Adding Conditions

To add conditions for the rule, follow the procedure in Section 10.27, Adding Conditions to a Rule.

10.12.5 Specifying Results for the Rule

To specify the results for if the rule triggers, follow the procedure in Section 10.21.3, Specifying the Results for a Rule. You can select from the following types of results: ■ Score and Weight ■ Actions An action is an event activated when a rule is triggered. For example: block access, challenge question, ask for PIN or password, and so on. For information about action groups, see Chapter 12, Managing Groups. ■ Alerts An alert is a message generated when a rule is triggered. For example: login attempt from a new country for this user. For information about alert groups, see Chapter 12, Managing Groups. Table 10–4 New Rule Page Field Description Rule Name Name of the rule. Enter between 1 and 4000 characters. Policy Name Name of the policy. Read-only Rule Status Status of the rule: Active or Disabled. If the rule status is changed from Active to Disabled, the rule is disabled and cannot be added to a policy. A policy that already contains the rule is not affected and continues to function as before. Description Description for the rule. Enter between 1 and 4000 characters. 10-20 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

10.12.6 Adding or Copying a Rule to a Policy

The Copy Rule button enables you to copy an existing rule to other policies.

10.13 Working with Trigger Combinations

Trigger combinations enable you to specify outcomes different from the ones for the individual rules. The outcomes are based strictly on the combinations of rule triggers. You can specify a score, action group and alert group based on different rule return combinations or you can point to nested policies to further evaluate the risk. The trigger combinations evaluate sequentially, stopping as soon as a trigger combination is matched. Figure 10–9 Trigger Combination Structure Trigger Combinations can be access through the Rule Details page. Each column in the table corresponds to a trigger combination. Managing Policies, Rules, and Conditions 10-21 Figure 10–10 Trigger Combinations By default the rules are set to Any. Any ignores the rule whether or not it triggers. The total number of trigger combinations in the policy appears in parenthesis next to the tab title. The first column is frozen to enable you to scroll and see all of the data in the table while having the labels available for reference. For information about Action and Alert groups, see Chapter 12, Managing Groups.