Hi,
I was wondering if someone can explain the Risk based profile acceptance (allowed) and timeframe; I'll explain, in doing Immpossible travel testing the first time I dit it was testing from a VPN through Norway after just logging in from Canada. The first time I did this I got the elevated prompt for more authentication and this worked as expected.
Since then it has never elevated the authentication even though I am logging in within a few seconds to an app from the other side of the world. The only thing I can think of is the RBP drops something on the PC or uses the GUID or something to say this is acceptable behavior and don't elevate auth.
In this scenario (impossible travel) it should always elevate the auth, so I wanted to know how it assesses risk and what is deemed acceptable and for how long?
Thanks in advance