Risk-Based Authentication Message Policy
The risk-based authentication (RBA) message policy defines the message that users see when they are prompted to configure their identity confirmation method. You might use this message to inform users about why they need to configure an identity confirmation method. This message displays when all of the following conditions exist:
The user authenticates to a web-based application, such as an SSL-VPN, thin client, or web portal.
The user has not configured an identity confirmation method.
The user attempts to authenticate using a high assurance device.
You can assign an RBA message policy to any security domain. A deployment can have multiple RBA message policies, which you assign by editing the security domain. Security domains use the deployment’s default RBA message policy until you assign a different RBA message policy.
Related Tasks
Add a Risk-Based Authentication Message Policy
Edit a Risk-Based Authentication Message Policy
Delete a Risk-Based Authentication Message Policy
Duplicate a Risk-Based Authentication Message Policy
Change the Default Risk-Based Authentication Message Policy
Assign a Risk-Based Authentication Message Policy to a Security Domain
Related Articles
Duplicate a Risk-Based Authentication Message Policy 5Number of Views Implementing Risk-Based Authentication 41Number of Views Change the Default Risk-Based Authentication Message Policy 3Number of Views Risk-Based Authentication 47Number of Views Risk-Based Authentication Policies 25Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Announces RSA Authentication Manager 8.9 Patch 2 Hotfix 1 and Updated Web-Tier Server