Chat now with support
Chat with Support

Security Analytics Engine 1.2 - User Guide

Security Analytics Engine Overview Plugins Conditions Shared Policies Applications Auditing Issued Alerts Policy Overrides Fallback Password

Adding a policy override

When a user has failed to authenticate due to a high risk score, you can create an override to allow that user access for a specified time period.

IMPORTANT: To avoid allowing a malicious user access to applications, only create an override when you are positive the user is legitimate.

IMPORTANT: Since adding an override causes the Security Analytics Engine to return a risk score of 0, alerts will not be sent for the user until the override has expired.

To add a policy override

  1. From the left pane, click Reports to open the Reports page.
  2. From the Reports page, click Auditing to open the Auditing page. By default, the audit events for the current date are displayed.
  3. Select a risk score event from the list that is associated with the user (see Filtering the audit events for information on locating a specific event and/or an event from a previous date).
  4. Click the Override button to open the Add Override dialog.
  5. The name of the user appears in the User Name field. Verify that this is the correct user for the override.

    NOTE: This field cannot be edited.
  6. For Browser ID, select the browser ID that corresponds to the selected audit event or select Any to allow any browser.
  7. In the User Address field, select the IP address that corresponds to the selected audit event or select Any to allow any IP address.
  8. In the Expires in field, use the following drop-down menus to specify the length of time the override will apply. The override must last a minimum of 30 minutes.
    • Days - Select the number of days the override will be in effect (0 to 31). By default, this is set to 1.
    • Hours - Select the number of hours the override will be in effect (0 to 23). By default, this is set to 0.
    • Minutes - Select the number of minutes the override will be in effect (0 to 59). By default, this is set to 0.
  9. Click the Save button to save the override and close the dialog. The override is now in effect and alerting has been stopped for the user until the specified expiration time.

Editing a policy override on the Auditing page

NOTE: Once created, policy overrides can also be managed from the Policy Overrides page which lists all active policy overrides.

IMPORTANT: Since adding an override causes the Security Analytics Engine to return a risk score of 0, alerts will not be sent for the user until the override has expired.

To edit a policy override

  1. From the left pane, click Reports to open the Reports page.
  2. From the Reports page, click Auditing to open the Auditing page. By default, the audit events for the current date are displayed.
  3. Select a risk score event from the list that is associated with a current override. See Filtering the audit events for information on locating a specific event and/or an event from a previous date.
  4. Click the Override button to open the Modify Override dialog.
  5. The following information is displayed for the override:
    • Last Updated By: <nn> - The username of the administrator or help desk operator that last created or modified the override.

      NOTE: This field cannot be edited.
    • User Name - The name of the user to whom the override applies.

      NOTE: This field cannot be edited.
    • Browser ID - The browser ID to which the override applies.
    • User Address - The IP address to which the override applies.
    • Expires In - The time left before the override expires. The override must last a minimum of 30 minutes.

    Make any necessary changes to the override.

  6. Click the Save button to save the changes to the override and close the dialog. The changes to the override are now in effect and alerting is still stopped for the user the specified expiration time.

Deleting a policy override on the Auditing page

NOTE: Once created, policy overrides can also be managed from the Policy Overrides page which lists all active policy overrides.

To delete a policy override

  1. From the left pane, click Reports to open the Reports page.
  2. From the Reports page, click Auditing to open the Auditing page. By default, the audit events for the current date are displayed.
  3. Select a risk score event from the list that is associated with a current override. See Filtering the audit events for information on locating a specific event.
  4. Click the Override button to open the Modify Override dialog.
  5. Click the Delete button to delete the policy override.
  6. A confirmation dialog appears. Click the Delete button. Risk scores will now be reported and alerting is enabled for the user.

Issued Alerts

Topics:
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating