Once configured, a global policy applies to all integrated authentication solution IDs under your Alibaba Cloud account. It primarily provides endpoint risk detection and phone number risk detection to help prevent fraudulent activities. This topic describes how to configure a global policy in the console.
View the global policy
Log on to the Phone Number Verification Service console.
In the left-side navigation pane, choose Converged Authentication > Authentication Policy Settings.
On the global policy page, select a scenario and configure the policy as prompted.
The following table describes the available scenarios.
Scenario
Description
One-click phone number logon/registration
Used for scenarios where you need to verify a user's phone number during their initial logon. Users can complete the registration or logon process with a single click.
Change phone number
Used for scenarios where a user changes their phone number.
Example: A user gets a new phone number and needs to update the phone number associated with their account.
Reset password
Used for scenarios where a user has forgotten their password and needs to reset it.
Bind new phone number
Used for scenarios where a user binds a new phone number.
Example: After a user logs in with an account from a different system, they are prompted to bind their phone number.
Verify bound phone number
Used for business processes that require verifying the current phone number before proceeding.
Example: When creating a new Alibaba Cloud account, the user must verify their current phone number to complete the process.
In the policy configuration section, configure the policies for each scenario.
Scenario
Policy configuration
One-click phone number logon/registration
Endpoint risk detection
Phone number risk detection
Phone number verification
SMS authentication
User-initiated SMS authentication
Phone number scoring
Change phone number
Endpoint risk detection
Phone number risk detection
SMS authentication
User-initiated SMS authentication
Reset password
Endpoint risk detection
Phone number risk detection
SMS authentication
User-initiated SMS authentication
Bind new phone number
Endpoint risk detection
Phone number risk detection
SMS authentication
User-initiated SMS authentication
Verify bound phone number
Endpoint risk detection
SMS authentication
User-initiated SMS authentication
Policy configuration
Endpoint risk detection
Select a scenario and, in the policy configuration section, double-click endpoint risk detection.
On the endpoint risk detection page, click Modify Configuration.
Configure the parameters as prompted.
Parameter
Description
Score settings
Set a score. The endpoint risk score ranges from 0 to 100.
NoteA higher score indicates greater risk.
If the endpoint risk score is at or below the configured value, the process continues. Otherwise, the process is routed to user-initiated SMS authentication.
Rule settings
Set rules. Click +Add Rule to add a rule.
NoteYou can add a maximum of five rules.
If the frequency control conditions match any rule, the flow proceeds to user-initiated SMS authentication.
NoteClick Restore to Default to restore all parameters to their default settings.
Click OK to save the settings.
Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.
Phone number risk detection
Select a scenario and, in the policy configuration section, double-click phone number risk detection.
On the phone number risk detection page, click Modify Configuration.
Configure the parameters as prompted.
Parameter
Description
Score settings
Set a score. The risk score ranges from 0 to 100.
NoteA higher score indicates greater risk.
If the risk score meets or exceeds the configured value, the phone number is considered high-risk, and the process is routed to user-initiated SMS authentication.
User interface settings
Set the minimum interval, in seconds, between sending attempts for each phone number.
Phone number frequency control
Set rules for phone number frequency control. Click +Add Rule to add a rule.
NoteYou can add a maximum of five rules.
If any rule is matched, the flow proceeds to user-initiated SMS authentication.
NoteClick Restore to Default to restore all parameters to their default settings.
Click OK to save the settings.
Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.
Phone number verification
Select a scenario and, in the policy configuration section, double-click phone number verification.
On the phone number verification page, click Modify Configuration.
Configure the Authentication settings as prompted.
Set the timeout for the phone number verification. If the request times out, the process proceeds to SMS authentication. You can also specify the fallback action if the API call fails.
NoteClick Restore to Default to restore all parameters to their default settings.
Click OK to save the settings.
Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.
SMS authentication
Select a scenario and, in the policy configuration section, double-click SMS authentication.
On the SMS authentication page, click Modify Configuration.
Configure the parameters as prompted.
Parameter
Description
SMS signature
Select an SMS signature. If you do not have a signature, click Add Custom Signature to add a signature.
SMS template
Select an SMS template. If you do not have a template, click Add Custom Template to add a template.
Verification code validity period
Set the validity period for the verification code.
Verification code rule
Set the rule for the verification code, such as the number of random digits.
NoteClick Restore to Default to restore all parameters to their default settings.
Click OK to save the settings.
Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.
User-initiated SMS authentication
Select a scenario and, in the policy configuration section, double-click user-initiated SMS authentication.
On the user-initiated SMS authentication page, click Modify Configuration.
Set the SMS content validity period.
NoteClick Restore to Default to restore all parameters to their default settings.
Click OK to save the settings.
Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.
Phone number scoring
Select a scenario and, in the policy configuration section, double-click phone number scoring.
On the phone number scoring page, click Modify Configuration.
Enable or disable this feature.
NoteClick Restore to Default to restore all parameters to their default settings.
Click OK to save the settings.
Click OK to complete the setup. The changes take 5 to 10 minutes to take effect.