Global policy

更新时间:
复制 MD 格式

Once configured, a global policy applies to all integrated authentication solution IDs under your Alibaba Cloud account. It primarily provides endpoint risk detection and phone number risk detection to help prevent fraudulent activities. This topic describes how to configure a global policy in the console.

View the global policy

  1. Log on to the Phone Number Verification Service console.

  2. In the left-side navigation pane, choose Converged Authentication > Authentication Policy Settings.

  3. On the global policy page, select a scenario and configure the policy as prompted.

    The following table describes the available scenarios.

    Scenario

    Description

    One-click phone number logon/registration

    Used for scenarios where you need to verify a user's phone number during their initial logon. Users can complete the registration or logon process with a single click.

    Change phone number

    Used for scenarios where a user changes their phone number.

    Example: A user gets a new phone number and needs to update the phone number associated with their account.

    Reset password

    Used for scenarios where a user has forgotten their password and needs to reset it.

    Bind new phone number

    Used for scenarios where a user binds a new phone number.

    Example: After a user logs in with an account from a different system, they are prompted to bind their phone number.

    Verify bound phone number

    Used for business processes that require verifying the current phone number before proceeding.

    Example: When creating a new Alibaba Cloud account, the user must verify their current phone number to complete the process.

    In the policy configuration section, configure the policies for each scenario.

    Scenario

    Policy configuration

    One-click phone number logon/registration

    • Endpoint risk detection

    • Phone number risk detection

    • Phone number verification

    • SMS authentication

    • User-initiated SMS authentication

    • Phone number scoring

    Change phone number

    • Endpoint risk detection

    • Phone number risk detection

    • SMS authentication

    • User-initiated SMS authentication

    Reset password

    • Endpoint risk detection

    • Phone number risk detection

    • SMS authentication

    • User-initiated SMS authentication

    Bind new phone number

    • Endpoint risk detection

    • Phone number risk detection

    • SMS authentication

    • User-initiated SMS authentication

    Verify bound phone number

    • Endpoint risk detection

    • SMS authentication

    • User-initiated SMS authentication

Policy configuration

Endpoint risk detection

  1. Select a scenario and, in the policy configuration section, double-click endpoint risk detection.

  2. On the endpoint risk detection page, click Modify Configuration.

  3. Configure the parameters as prompted.

    Parameter

    Description

    Score settings

    Set a score. The endpoint risk score ranges from 0 to 100.

    Note
    • A higher score indicates greater risk.

    • If the endpoint risk score is at or below the configured value, the process continues. Otherwise, the process is routed to user-initiated SMS authentication.

    Rule settings

    Set rules. Click +Add Rule to add a rule.

    Note
    • You can add a maximum of five rules.

    • If the frequency control conditions match any rule, the flow proceeds to user-initiated SMS authentication.

    Note

    Click Restore to Default to restore all parameters to their default settings.

  4. Click OK to save the settings.

  5. Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.

Phone number risk detection

  1. Select a scenario and, in the policy configuration section, double-click phone number risk detection.

  2. On the phone number risk detection page, click Modify Configuration.

  3. Configure the parameters as prompted.

    Parameter

    Description

    Score settings

    Set a score. The risk score ranges from 0 to 100.

    Note
    • A higher score indicates greater risk.

    • If the risk score meets or exceeds the configured value, the phone number is considered high-risk, and the process is routed to user-initiated SMS authentication.

    User interface settings

    Set the minimum interval, in seconds, between sending attempts for each phone number.

    Phone number frequency control

    Set rules for phone number frequency control. Click +Add Rule to add a rule.

    Note
    • You can add a maximum of five rules.

    • If any rule is matched, the flow proceeds to user-initiated SMS authentication.

    Note

    Click Restore to Default to restore all parameters to their default settings.

  4. Click OK to save the settings.

  5. Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.

Phone number verification

  1. Select a scenario and, in the policy configuration section, double-click phone number verification.

  2. On the phone number verification page, click Modify Configuration.

  3. Configure the Authentication settings as prompted.

    Set the timeout for the phone number verification. If the request times out, the process proceeds to SMS authentication. You can also specify the fallback action if the API call fails.

    Note

    Click Restore to Default to restore all parameters to their default settings.

  4. Click OK to save the settings.

  5. Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.

SMS authentication

  1. Select a scenario and, in the policy configuration section, double-click SMS authentication.

  2. On the SMS authentication page, click Modify Configuration.

  3. Configure the parameters as prompted.

    Parameter

    Description

    SMS signature

    Select an SMS signature. If you do not have a signature, click Add Custom Signature to add a signature.

    SMS template

    Select an SMS template. If you do not have a template, click Add Custom Template to add a template.

    Verification code validity period

    Set the validity period for the verification code.

    Verification code rule

    Set the rule for the verification code, such as the number of random digits.

    Note

    Click Restore to Default to restore all parameters to their default settings.

  4. Click OK to save the settings.

  5. Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.

User-initiated SMS authentication

  1. Select a scenario and, in the policy configuration section, double-click user-initiated SMS authentication.

  2. On the user-initiated SMS authentication page, click Modify Configuration.

  3. Set the SMS content validity period.

    Note

    Click Restore to Default to restore all parameters to their default settings.

  4. Click OK to save the settings.

  5. Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.

Phone number scoring

  1. Select a scenario and, in the policy configuration section, double-click phone number scoring.

  2. On the phone number scoring page, click Modify Configuration.

  3. Enable or disable this feature.

    Note

    Click Restore to Default to restore all parameters to their default settings.

  4. Click OK to save the settings.

  5. Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.