OAAM doubt!
Does OAAM remembers the device finger printing information and maintains it in database persistently or just maintains it for a single session only.
Gone through some docs and that this information is being updated multiple times even during active session. However, the documentation is not clear if user has to re-authenticate with 2nd factor authentication every time user accesses the application from the same device and same browser.
With OAAM 11g Risk Based Authentication, we have a standard requirement that if a user logs in from a new device/browser or laptop; then user will be challenged for 2nd level authentication on first time access of a secure app from that device. However then onward the user can access the secure application from that device without being challenged for 2nd factor authentication.