Risk Engine Considerations for Risk-Based Authentication
The risk-based authentication (RBA) risk engine creates a profile for each user based on the client device and user behavior. Before you deploy RBA, consider these factors regarding the RBA risk engine:
The RBA risk engine requires a learning period during which it acquires the data needed to build profiles on users and their devices, and general user population behavior. During this learning period, users may be challenged more frequently for risk until the profiles are built to establish baseline assurance levels. For user convenience, you can configure the silent collection option to avoid risk-based challenges while the data for baseline assurance levels is acquired. See Silent Collection.
The RBA risk engine employs soft matching techniques based on statistical probability. If the risk engine has insufficient data to match a device, it can use forensic tools to assess the match probability and adjust the assurance level accordingly.
The RBA risk engine is self-tuning and learns to ignore parameter values that most authentications in your deployment have in common. Self-tuning improves security and reduces overall user challenge rates.
Related Articles
Configure Device Registration for a Risk-Based Authentication Policy 7Number of Views RSA Identity Governance & Lifecycle aveksaServer.log repeatedly shows "updateServerAgentUptimeDate: Setting new uptime for… 71Number of Views RSA Federated Identity Manager (FIM) 2.0 shows very high memory usage when under load using DSig 12Number of Views Symptoms of a failed memory module on RSA SecurID hardware appliance 61Number of Views Upgrading the Internal SecurID Authentication Manager 8.6 Certificates to SHA-256 490Number of Views
Trending Articles
RSA Release Notes for RSA Authentication Manager 8.8 RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to factory reset an RSA SecurID hardware appliance running Authentication Manager 8.2 without using the installation I… Software Token Profiles Update Identity Router Software