Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


...

Div
classbreadcrumbs

/wiki/spaces/E2D/pages/29982926  /  Single Sign-On and MFA  /  Multi-Factor Authentication  /  Current: Assigning Adaptive Authentication Rules to Applications


Anchorassigning-adaptive-authentication-rules-to-applicationsassigning-adaptive-authentication-rules-to-applications

Adaptive Authentication rules can be assigned to any SSO application to force users to undergo further identity proofing before they can access that application under certain circumstances. EmpowerID provides two Adaptive Authentication rules that can be assigned to applications out of the box, the CheckLoginSpeed and the CheckUserDemographics rule.

  • CheckLoginSpeed - This rule checks the current time and location of the person attempting to access the application against the time and location of their last login to determine whether that person could reasonably do so under normal circumstances. For example, if the person logged in at 9:00AM from their office in Boston and then attempted to log in 45 minutes later from Seattle, this rule would consider the second log in attempt questionable as it would be impossible for the user to travel from Boston to Seattle in 45 minutes. The rule would then force the user to undergo further identity proofing.
  • CheckUserDemographics - This rule checks for missing person attributes, such as the user address or job title. If these attributes are missing, EmpowerID prompts the user to enter the missing information before proceeding to the application.


Info

If your organization needs more rules, you can create them in Workflow Studio and publish them to your environment. Once published, you can add them to to your

SSO applications

Password Manager policies as shown in this article.

anchor

mfaPoliciesmfaPolicies


To assign Adaptive Authentication to

Applications

Password Manager Policies

  1. From the Navigation Sidebar
, navigate to the Applications management page by expanding Applications and clicking Manage Applications. From the Applications tab of the Applications management
  1. of the EmpowerID Web interface, expand Admin > Polices and click Password Manager Policies.
  2. From the Policies tab of the Password Manager Policies page, search for the
application
  1. policy to which you want to add an Adaptive Authentication Rule and then click the Display Name link for that
application
  1. policy.
Image Removed


  1. Image Added


    This opens the This opens the Application Details page for the application. This page allows you to view information about the application and manage it as needed.
Image Removed

  1. Image Added


  2. From the
Application
  1. Policy Details page that appears, expand the Adaptive Authentication Rules accordion and then click the Add Rule (+) button to the right of the grid.
Image Removed


  1. Image Added


  2. In the dialog that appears, do the following:
    1. Select the rule you want to assign to the
application
    1. policy from the Rule drop-down.
    2. Set the priority for the rule in the Priority field. The lower the number the higher the priority. When more than one Rule is assigned to an application, EmpowerID directs users to the rule with the highest priority first and then to the rule with the next highest priority and so on.
    3. Click Save.
Related Topics Anchorconceptsconcepts

Concepts:

Anchoradministrative-proceduresadministrative-procedures

Administrative Procedures:

Anchoruser-tasksuser-tasks

User Tasks

  • Using Duo Two-Factor Authentication
  • Using Yubikey OTP
  • Using OATH Tokens
  • Using FIDO Universal 2nd Factor
  • Using EmpowerID One-Time Password
  • Using Device Registration

      1. Image Added



    Rw ui expands macro


    Rw ui expand macro
    titleRelated Content





    trueConcepts






    trueAdministrative Tasks






    trueUser Tasks