This section describes the authentication and risk flow for an end user who is enrolled but is using a different device to which the ArcotID OTP credential has not been provisioned.
The end user is authenticated as follows:
The resulting help page provides three links to enroll for advanced authentication, reset PIN, and perform roaming authentication.
Note: If security question was used the first time, then security code is used in this step. Conversely, if security code was used the first time, then security question is used in this step.
Notes:
For example, if security question or security code over email is enabled for roaming authentication, and security question or security code over SMS is enabled for risk authentication, and if the end user selects security question first and is authenticated successfully, they are not authenticated again during the risk flow. However, if the end user selects security code over email the first time and is authenticated successfully, then in the risk flow, the user is authenticated again using security question.
In another example where security question or security code over email is enabled for roaming authentication, and security question and security code over SMS are enabled for risk authentication, if the end user selects security question in the roaming flow and is authenticated successfully, then in the risk flow, the security code over SMS method is invoked. However, if the end user selects security code over email in the roaming flow, then both security question and security code over SMS are invoked in the risk flow.
A risk cookie is placed on the end user's device. During subsequent logins, the risk history is used to decide whether to grant access to the end user after authentication.
|
Copyright © 2013 CA.
All rights reserved.
|
|