Organizations are increasingly seeking to implement phishing-resistant multifactor authentication (MFA), adaptive security, and passwordless access to secure their enterprise resources against cyber threats. For many organizations, these measures are critical to achieve regulatory compliance as outlined in the United States’ Zero-Trust Memorandum (M-22-09), the Australian Government’s Essential Eight, or the European Union’s Digital Operational Resilience Act.
Oracle Access Management and its microservices, Oracle Advanced Authentication, Oracle Universal Authenticator, and Oracle Adaptive Risk Management, help organizations enable modern MFA for applications and devices. Oracle Advanced Authentication (OAA) provides modern MFA factors out-of-the-box which assert a user’s identity before granting access. OAA supports phishing-resistant MFA methods, like biometrics and FIDO2-enabled security keys, such as passkeys or hardware keys like YubiKey, in addition to common, user-friendly methods like mobile push notifications or time-based one-time passwords (TOTP). OAA seamlessly integrates with Oracle Universal Authenticator (OUA), a unified authentication solution that provides device authentication and cross-platform single-sign on (SSO) to web-based and desktop applications. Oracle Adaptive Risk Management (OARM) enables conditional, risk-based authentication offering comprehensive fraud monitoring, analysis, and tracking based on factors such as user location, device, and time of day. All these factors are evaluated against a set of customizable rules.
Now, implementing these solutions is easier than ever. We’re excited to announce the latest advancements to the installation and deployment experience of OAA. With the latest updates to OAA, a plethora of prerequisite and post-installation steps, which previously required manual input, are now automated, reducing the risk of human error and system misconfigurations and ultimately saving you time.
With the latest update, existing Oracle Access Management (OAM) customers running the appropriate 12cPS4 bundle patches with a Kubernetes cluster setup can enable MFA in an afternoon! You can quickly configure all your applications protected by OAM, whether on-premises or in the cloud, to be secured by modern MFA methods, such as push notifications, TOTP, FIDO2 security keys, and biometric authentication, all with zero application code changes. Examples include applications like Oracle and non-Oracle applications, such as Fusion Applications, E-Business Suite (EBS), employee portal, and custom-built web applications, among many others.
OAA, OUA, and OARM are cloud native, containerized microservices offering flexible deployment options, with standalone deployment available for OAA and OARM. These microservices are especially optimized for Oracle Kubernetes Engine (OKE) environments, but you can also deploy them in any Cloud Native Computing Foundation (CNCF)-compliant Kubernetes environments in the cloud or on-premises.
Oracle is continually innovating to support enterprises on their MFA enablement journeys with highly scalable, reliable, and feature-rich solutions that bolster security and help with adherence to regulatory compliance.
To start your journey toward phishing-resistant MFA and passwordless security today, see the following resources:
Previous Post
Next Post