Device History for Risk-Based Authentication
For risk-based authentication (RBA), the system maintains a device history for each user. The device history is a list of user authentication devices from previous successful logons. Once added to the list, the device is considered to be registered. When the user tries to access an RBA-protected resource using a registered device, the authentication attempt is likely to have a higher assurance level.
User authentication devices are the physical devices from which the user requests access to an RBA-protected resource. They include computers and mobile devices, but do not include authenticators.
During silent collection, the system adds all authentication devices to the user's device history automatically. When silent collection expires or is disabled, the system saves all devices to the device history automatically, or prompts the user to choose to add the device to the device history, depending on the RBA policy settings.
To manage the device history, you can:
View the number of devices in the user device history. For more information, see View Risk-Based Authentication Settings for a User.
Delete the device history. Delete the device history when a user reports a device as lost or stolen, or accidentally registers a device that is a public or shared computer. For more information, see Delete the Device History for a User.
Configure how the system responds when the user's device is not already saved in the device history. For more information, see Configure Device Registration for a Risk-Based Authentication Policy.
Set the maximum number of registered devices preserved in each user’s device history. For more information, see Configure Device History Settings for a Risk-Based Authentication Policy.
Set when a device expires. The system removes expired devices from the device history. For more information, see Configure Device History Settings for a Risk-Based Authentication Policy.
Related Articles
Edit a Risk-Based Authentication Message Policy 4Number of Views Log Files for Bulk Requests 13Number of Views Maintain Authentication Agent Associations in a Duplicated User Group 14Number of Views Log Rotation Policy for the Appliance Logs 57Number of Views A customer requests that a BIN in TEST environment be moved into PRODUCTION environment This procedure explains and provid… 15Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS