Troubleshooting: Adaptive Authentication Factors After IP Reputation/Threat Data Are Not Applied

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    When multiple Adaptive Authentication factors are enabled on a realm, any factor listed after IP Reputation/Threat Data — such as IP/Country Restriction, as shown below — is never evaluated.

    Adaptive Authentication tab showing IP Reputation/Threat Data listed above IP/Country Restriction in the ordered list of factors.

     

    Cause

    The IP Reputation/Threat Data factor's failure action is set incorrectly — for example, to Resume auth, as shown below.

    IP Reputation/Threat Data Low Risk failure action set to Resume auth.

    A failure action other than Disable causes SecureAuth to skip the remaining Adaptive Authentication factors entirely, bypassing whatever additional checks they perform.

     

    Resolution:

    Change the IP Reputation/Threat Data factor's failure action to Disable. This setting name is misleading — it does not disable the IP Reputation/Threat Data check itself. Instead, it means the factor takes no independent action on its own, and lets authentication continue through the rest of the configured Adaptive Authentication factors.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.