You can manage a user's risk-based authentication settings. When you change these settings, the user's settings override the system-wide settings you set in the general system-wide risk-based authentication settings (see Modify risk-based authentication general settings.
You can manage the following user risk-based settings:
● Location History
When a user logs in to Identity as a Service, the location the user used to log in is added to the user's location history, as follows:
– Authentication from a public location
Identity as a Service converts the IP address to location data and stores the location information, such as country, city, latitude and longitude of the location, ISP name, IP address, date and time of the authentication and the number of times the user authenticated from the location.
Location comparisons that involve public locations look at the country, city, and ISP. The IP address is also used in the comparison if the Check IP Address in Location History setting is enabled. If all comparison items match exactly, the two locations are considered the same and the test passes. If there is any difference—even a minor spelling variation for the ISP name— the test fails and the user receives the risk points associated with that condition. Those risk points contribute to the user's total risk score during their authentication attempt.
– Authentication from a private location
When a user log in to Identity as a Service from a private location, Identity as a Service stores the IP address, date and time of the authentication, and the number of times the user authenticated from the location.
● Expected Locations
The Expected Locations list contains IP locations that users are expected to log in from. You can move a location from the Location History to a user's Expected Locations List
● Settings
You can set whether the user uses the system-wide risk-based authentication settings or the user-specific settings.
Move
location history to expected locations, add expected locations, and delete
location history
Add
or delete expected location
Set
the user risk-based authentication settings