The Policy Server maintains authorization services in an integrated environment and can apply the risk score to authorization decisions. The risk score is created during the authentication process.
The Policy Server applies the risk score as a SiteMinder confidence level. A confidence level is based on a risk score, and as such, is also an integer that represents the likelihood that the transaction is safe.
The following example workflow details the relationship between both values and explains how the Policy Server applies a confidence level to authorization decisions:
(100-risk score) * 10 = confidence level
Note: For more information about session tickets, see the Policy Server Configuration Guide.
Note: If the user’s confidence level is less than the confidence level configured in the policy, SiteMinder denies access.
Note: For more information about adding a confidence level to policies, see the Policy Server Configuration Guide.
Copyright © 2012 CA.
All rights reserved.
|
|