Risk evaluation calculates the risk result and sets the access based on low, medium, and high risk. All risk factors are connected to the Risk Evaluation node. The Risk Evaluation must include an access result to set authentication requirements to allow or deny access.
The following example shows a risk evaluation that requires second-factor authentication only if the risk is low, password and second-factor authentication for medium risk, and deny access for high risk.

 Configure the risk evaluation and save 
 the resource rule
Configure the risk evaluation and save 
 the resource rule