Manage risk profiles

A risk profile is a collection of attributes with assigned weights. We can view a list of profiles or to add, delete, or clone profiles or set a profile to active. Only one risk profile can be active at a time.

Several risk profiles are predefined based on risk assessment for a collection of attributes. Predefined risk profiles are read only and we cannot modify their weights or add attributes to them. We can add custom risk profiles by creating our own or by cloning an existing profile.

By default, a risk profile named Default is set to active. The Default profile includes all the risk profile attributes with weights set to 0. With this profile active, if a user logs in with no devices registered, the risk score of that user is 100. If a user logs in with a device registered, the risk score of that user is 0. The Default profile is a sample profile. It is not intended to be used in a production environment. Before we use Security Verify Access, choose another risk profile or create our own. Use single-value attributes when we create a risk profile. Multivalue attributes are not supported in risk profiles. There are two sections on the Risk Profile page:

Steps

  1. Log in to the local management interface.

  2. Click AAC.

  3. Under Policy, click Risk Profiles.

  4. Perform one or more of the following actions:

      Rename a risk profile

      1. Right-click the profile name in the table and click Rename to change the name. The risk profile name must begin with an alphabetic character. Do not use control characters, leading and trailing blanks, and the following special characters ~ ! @ # $ % ^ & * ( )  + | ` = \ ; :  " ' < > ? , [  ] { } / anywhere in the name.
      2. Press Enter to apply the change.

      Modify a custom profile
      We can modify only custom profiles.

      1. Select a custom profile.

      2. Modify the attributes and associated weights in the Selected Profile Contents section.

      Create a custom profile

      1. Click Add.

      2. Type a name for the profile. Click Save.

      3. In the Profile Contents section, click Add attribute to add one or more attributes.

      4. In the Add Profile Attributes window, select an attribute to use. Click the Attribute column to sort the list in ascending or descending order. To filter the list of available attributes, type one or more characters in the Filter field. For example, if you type current in the Filter field, all attributes that start with current are shown in the attributes list. The attributes that match those characters are displayed.

      5. Select one or more attributes to add.

      6. Click Add.

      7. Click Close when we are done with the Add Profile Attributes window.
      8. Change the weights by typing or selecting a number.

      9. Click Save to apply the changes.

      10. To make this new profile active, click Set active Set Active.

      Create a copy of a profile and use it to make a custom profile

      1. Select the profile to clone and give the profile a unique name.

      2. Click Duplicate.

      3. Type a new name for the cloned profile.

      4. Click Save.

      5. Clone.

      6. In the Profile Contents section, select an attribute and take one of the following actions:

        • Type a new value in the Weight field.

        • Click Remove attribute to remove both the attribute and weight.

        • Click Add attribute to add one or more attributes. In the Add Profile Attribute window, select the attributes to use. To filter the list of available attributes, type one or more characters in the Filter field. The attributes that match those characters are displayed. For example, if you type header in the Filter field, all attributes that start with header are shown in the attributes list. Select the attribute to use in the list and click Add. Click Close when we are done with the Add Profile Attributes window.

      7. Click Save after each change to apply the change.

      8. To make this new profile active, click Set active Set Active.

      Delete a risk profile

      1. Select a risk profile. We cannot remove predefined risk profiles.

      2. Click Delete.
      3. Respond to the confirmation prompt.

      The risk profile is removed and cannot be used.

      Make a profile active

      1. Select a profile.

      2. Click Set active Set Active. Only one profile can be active at a time.

  5. When we add, modify or delete a risk profile, a message indicates there are changes to deploy. If we are finished with the changes, deploy them.

    For information, see Deploying pending changes.

Parent topic: Risk profiles