{"title":"Dynamic 3D Secure","category":"default","creationDate":1678279200,"content":"<p>When you support <a href=\"\/online-payments\/3d-secure\">3D Secure 2<\/a> in your website or mobile app, and send in a payment request, 3D Secure authentication can be triggered for the transaction. You can use the <a href=\"#default-rules\">default 3D Secure rule<\/a> and <a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure<\/a> rules to make sure 3D Secure is requested and, in special cases, to request a 3D Secure challenge.<\/p>\n<h2>Requirements<\/h2>\n<p>Before you begin, take into account the following requirements and limitations.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\">Requirement<\/th>\n<th style=\"text-align: left;\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align: left;\"><strong>Integration type<\/strong><\/td>\n<td style=\"text-align: left;\">Make sure that you have built an <a href=\"\/online-payments\/build-your-integration\/\">online payments integration<\/a>, and that you have implemented <a href=\"\/online-payments\/3d-secure\/\">3D Secure 2<\/a>.<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong><a href=\"\/account\/user-roles\/#risk\">Customer Area roles<\/a><\/strong><\/td>\n<td style=\"text-align: left;\">To add or change <a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rules<\/a>, make sure that you have one of the following role(s): <ul><li markdown=\"1\"><strong>Merchant change risk settings<\/strong><\/li><li markdown=\"1\"><strong>Management Dynamic 3D Secure Rules<\/strong><\/li><\/ul><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Limitations<\/strong><\/td>\n<td style=\"text-align: left;\">To use Dynamic 3D Secure in combination with risk management, <a href=\"\/risk-management\/configure-risk-settings\/\">risk must be enabled<\/a>. Protect <a href=\"\/risk-management\/configure-risk-settings\/#risk-general\">premium features<\/a> must be enabled to: <ul><li markdown=\"1\">Use <a href=\"#risk-based-authentication\">risk-based authentication<\/a>.<\/li><li markdown=\"1\">Create custom rules to link to <a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rules<\/a>.<\/li><\/ul><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Setup steps<\/strong><\/td>\n<td style=\"text-align: left;\">Implement <a href=\"\/online-payments\/3d-secure\/\">3D Secure 2<\/a>. Then: <ul><li markdown=\"1\">To use Dynamic 3D Secure: <ul><li><a href=\"\/risk-management\/dynamic-3d-secure#default-rules\">Configure the default 3D Secure rule<\/a> to specify your overall preferences.<\/li><li markdown=\"1\">Configure <a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rules<\/a> to create rules with more specific conditions.<\/li><\/ul><li markdown=\"1\">To override any Dynamic 3D Secure rules:<\/li><ul><li markdown=\"1\">Specify parameters in the <a href=\"#3ds-payment-request\">payment request<\/a>.<\/li><\/ul><\/ul><\/ol><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>How Dynamic 3D Secure works<\/h2>\n<p>To ensure that you stay compliant, we always authenticate transactions with 3D Secure if this is required by regulations such as <a href=\"\/online-payments\/psd2-sca-compliance-and-implementation-guide\">PSD2<\/a> or other market specific regulations. To mitigate any effects on conversion, we do not trigger 3D Secure for out-of-scope transactions, or when the issuing bank does not enforce 3D Secure. For transactions within the scope of PSD2, we also handle requesting <a href=\"\/online-payments\/psd2-sca-compliance-and-implementation-guide\/sca-exemptions\">exemptions<\/a>.<\/p>\n<p>You can use Dynamic 3D Secure to make sure 3D Secure is requested and, in special cases, to request a 3D Secure challenge. You can do this even if 3D Secure is not required by regulations or the issuer. This can be useful, for example, to make sure a liability shift takes place or to add more friction for high-risk transactions.<\/p>\n<p>You can specify your 3D Secure preferences using Dynamic 3D Secure as follows:<\/p>\n<ul>\n<li>Use the <a href=\"\/risk-management\/dynamic-3d-secure#default-rules\">default rule<\/a> as the setting to indicate your general preference to request 3D Secure. You can set this to <strong>Prefer not<\/strong> or <strong>Always<\/strong>. When set to <strong>Prefer not<\/strong>, Adyen can still decide to send the payment through 3D Secure because the issuer requires it, to ensure compliance with regulations, or to improve conversion. When set to <strong>Always<\/strong>, we will always request 3D Secure on your behalf.<\/li>\n<li>Create more specific <a href=\"\/risk-management\/dynamic-3d-secure#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rules<\/a>. You can set conditions to determine for which payments to <a href=\"#request-3ds\">request 3D Secure authentication<\/a>, and if you prefer to request a <a href=\"#request-3ds-challenge\">3D Secure challenge<\/a>.<\/li>\n<\/ul>\n<p>Alternatively, you can include <a href=\"#3ds-payment-request\">parameters in your payment request<\/a> to specify when a transaction should go through 3D Secure 2. And, when you use Protect premium, you can also benefit from <a href=\"#risk-based-authentication\">risk-based authentication<\/a>. Risk-based authentication sends transactions that would have been blocked by the machine learning fraud risk rule to 3D Secure 2.<\/p>\n<h2 id=\"default-rules\">Default 3D Secure rule<\/h2>\n<p>When you create a new <a href=\"\/account\/account-structure#company-account\">company account<\/a> or <a href=\"\/account\/account-structure#merchant-accounts\">merchant account<\/a>, the default rule is set to <strong>Prefer not<\/strong>.<br \/>\nChoose from the following possible settings:<\/p>\n<ul>\n<li><strong>Always<\/strong>: Use 3D Secure whenever possible. With this rule, there will still be transactions that do not go through 3D Secure authentication, for example, when the issuer doesn't support 3D Secure yet, or when the card isn't enrolled.<\/li>\n<li><strong>Prefer not<\/strong>: Do not apply 3D Secure authentication unless it is required by regulation or the issuer, or if it can help optimize performance.<\/li>\n<\/ul>\n<h2 id=\"configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rules<\/h2>\n<p>When you <a href=\"#configure-a-dynamic-3d-secure-rule\">configure a Dynamic 3D Secure rule<\/a>, you first specify the conditions to trigger the rule, and then you determine what happens when it triggers. When the rule triggers, you can specify what you want to do: <a href=\"#request-3ds\">request 3D Secure<\/a> and <a href=\"#request-3ds-challenge\">request a challenge<\/a>.<\/p>\n<h4 id=\"request-3ds\">Request 3D Secure<\/h4>\n<p>When you proactively request 3D Secure, you add an extra authentication layer to the payment flow. The transaction either goes through the <a href=\"\/online-payments\/3d-secure#challenge-flow\">challenge flow<\/a> or the <a href=\"\/online-payments\/3d-secure#authentication-flows\">frictionless flow<\/a> depending on the issuer.<\/p>\n<p>This can reduce the risk of fraud because a transaction with a successful 3D Secure authentication will result in a liability shift. This way, you can use Dynamic 3D Secure rules to mitigate the risk for certain transactions.<\/p>\n<p>It is important to understand that there is a trade-off. By requesting 3D Secure, you add friction. This friction impacts conversion because some shoppers might drop off. However, at the same time, if the authentication is successful, you reduce fraud and obtain a liability shift.<\/p>\n<h4 id=\"request-3ds-challenge\">Request a challenge<\/h4>\n<p>You can set your preference to present a challenge even if the frictionless flow is available. Both a successful <a href=\"\/online-payments\/3d-secure#challenge-flow\">challenge flow<\/a> and a successful <a href=\"\/online-payments\/3d-secure#authentication-flows\">frictionless flow<\/a> result in a liability shift. By default, to optimize conversion, a transaction will use the frictionless flow if it is available.<\/p>\n<p>Requesting a challenge is a way to add more friction because it requires additional shopper interaction. We recommend that you only set your preference to always request a 3D Secure challenge in special circumstances. This because the challenge adds significant friction and could lead to a higher shopper drop-off rate. Use it, for example, when you are experiencing extremely high fraud rates and requesting 3D Secure alone does not help.<\/p>\n<h3 id=\"configure-a-dynamic-3d-secure-rule\">Configure a Dynamic 3D Secure rule<\/h3>\n<p>There are few things to keep in mind when configuring Dynamic 3D Secure rules:<\/p>\n<ul>\n<li>Rules are evaluated in order, from first to last.<\/li>\n<li>If a rule is triggered, the remaining rules are not evaluated.<\/li>\n<li>You can configure rules on the company account, or on a merchant account. Rules configured on the merchant account have priority and only affect payments for that specific merchant account.<\/li>\n<li>Wherever possible, create several simple rules instead of combining many logic points into a single rule.<\/li>\n<li>Consider each separate condition that you specify within the rule as an AND statement. The rule will trigger if both conditions are met. However, when you select multiple values within a condition, the rule will trigger when any of these values are true.<\/li>\n<\/ul>\n<p>To configure a rule, in your <a href=\"https:\/\/ca-test.adyen.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Customer Area<\/a>:<\/p>\n<ol>\n<li>\n<p>Go to <strong>Revenue &amp; risk<\/strong> &gt; <strong>Dynamic 3D Secure<\/strong>.<\/p>\n<\/li>\n<li>\n<p>Select <strong>Create new rule<\/strong> to make a new rule or select the name of the rule if you want to modify an existing rule.<\/p>\n<\/li>\n<li>\n<p>Configure the criteria shown in the following table.<\/p>\n<p>You can combine criteria to create nested rules. For example, you may decide to use 3D Secure for every transaction where the issuing card is from Mexico and the transaction value is above USD&nbsp;100.<\/p>\n<table><colgroup><col style=\"width: 13%\"><col style=\"width: 86%\"><\/colgroup><thead><tr class=\"header\"><th><p>Criteria<\/p><\/th><th><p>Description<\/p><\/th><\/tr><\/thead><tbody><tr><td>\n<p>Issuer country<\/p>\n<\/td><td>\n<p>The country where the card was issued.<\/p>\n<\/td><\/tr><tr><td>\n<p>Shopper country<\/p>\n<\/td><td>\n<p>The country of the shopper, based on the IP address submitted with the payment.<\/p>\n<\/td><\/tr><tr><td>\n<p>Payment method<\/p>\n<\/td><td>\n<p>The card type (for example, American Express, Visa Platinum, etc. For more information, see <a href=\"\/development-resources\/paymentmethodvariant\">PaymentMethodVariant<\/a>).<\/p>\n<\/td><\/tr><tr><td>\n<p>Device type<\/p>\n<\/td><td>\n<p>The type of device that submitted the transaction. You can indicate mobile, desktop, or tablet devices.<div class=\"sc-notice note\"><div>The transaction must have device data submitted with it for this feature to work.<\/div><\/div><\/p>\n<\/td><\/tr><tr><td>\n<p>Amount<\/p>\n<\/td><td>\n<p>The transaction value. When you configure this for a specific currency, the rule will automatically convert to other currencies. For example, a EUR\u00a020 rule will automatically trigger for the equivalent amount in GBP.<\/p>\n<\/td><\/tr><tr><td>\n<p>Risk score<\/p>\n<\/td><td>\n<p>Do not use this condition, it does not apply to Protect. <br><br>The risk score condition was used in the classic risk engine to target transactions for 3D Secure when they met a certain risk score threshold.<\/p>\n<\/td><\/tr><tr><td>\n<p>BIN and BIN Range<\/p>\n<\/td><td>\n<p>The first six digits on a credit card. This identifies the Issuing bank of the card. For more information, read <a href=\"\/get-started-with-adyen\/adyen-glossary\/#bank-identification-number-bin\">Bank Identification Number (BIN)<\/a>. You can target a set or range of BINs, to use 3D Secure only for transactions from certain issuing banks.<\/p>\n<\/td><\/tr><tr><td>\n<p>Risk check<\/p>\n<\/td><td>\n<p>The pre-authorization <a href=\"\/risk-management\/configure-your-risk-profile\/custom-rules\/#create-a-custom-rule\">custom risk rule<\/a> with the <strong>Check for 3DS<\/strong> action that you want use to trigger 3D Secure.<\/p>\n<\/td><\/tr><\/tbody><\/table>\n<\/li>\n<li>\n<p>For each condition met, assign actions to request 3D Secure authentication, and your preference to present a challenge:<\/p>\n<ul>\n<li><strong>Request 3DS<\/strong>: If the condition is met, choose to apply any of the <a href=\"#default-rules\">default 3D Secure rules<\/a> (<strong>Prefer not<\/strong> or <strong>Always<\/strong>).<\/li>\n<li><strong>Request challenge<\/strong>: If you set up a rule where <strong>Request 3DS<\/strong> is set to <strong>Always<\/strong>, you also have the option to set your preference to request a challenge (<strong>Prefer not<\/strong> or <strong>Always<\/strong>).\n<div class=\"notices yellow\">\n<p>Setting request challenge to <strong>Always<\/strong> adds <a href=\"#request-3ds-challenge\">friction and can impact conversion negatively<\/a>. We recommend to use this in special circumstances only.<\/p>\n<\/div><\/li>\n<\/ul>\n<\/li>\n<li>\n<p>When you have created your rule, add a name for the rule and select <strong>Save<\/strong>. If you have updated an existing rule, also select <strong>Save<\/strong>.<\/p>\n<\/li>\n<li>\n<p>Rules are applied in the order they appear in the list. To set your preferences, move the most important rule to the top of the list, and order the rest of the rules in the order that you want them to be applied in and select <strong>Save<\/strong>.<\/p>\n<\/li>\n<\/ol>\n<h2 id=\"rule-configuration-examples\">Example scenarios<\/h2>\n<p>The following scenarios are some fictional examples to illustrate how you could set up Dynamic 3D Secure rules. You can create your own rules that follow your specific business needs and logic.<\/p>\n<h3 id=\"scenario-1\">Scenario 1<\/h3>\n<p>You are planning on expanding your business in Canada. You have previously used 3D Secure in the UK (where conversion rates are high), and you want to avoid using 3D Secure in Canada. All your traffic is from the UK and Canada.<\/p>\n<p>Rules you should set up:<\/p>\n<ol>\n<li><a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rule<\/a>: When the issuer country is <strong>Canada<\/strong>, then <strong>Prefer not<\/strong> to request 3D Secure.<\/li>\n<li><a href=\"#default-rules\">Default 3D Secure rule<\/a>: <strong>Always<\/strong> request 3D Secure for all other transactions.<\/li>\n<\/ol>\n<p>Only a <strong>Prefer not<\/strong> rule is needed since the default action is for transactions to use 3D Secure. With this setup, all UK transactions will use 3D Secure.<\/p>\n<h3 id=\"scenario-2\">Scenario 2<\/h3>\n<p>You are experiencing significant fraud in transactions above USD 200 in the US. You want an extra layer of authentication for these payments and a liability shift.<\/p>\n<p>Rules you should set up:<\/p>\n<ol>\n<li><a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rule<\/a>: When the amount is <strong>greater than USD 200<\/strong> AND the issuer country is <strong>United States<\/strong>, then <strong>Always<\/strong> request 3D Secure and <strong>Prefer not<\/strong> to request challenge.<\/li>\n<li><a href=\"#default-rules\">Default 3D Secure rule<\/a>: <strong>Prefer not<\/strong> to request 3D Secure authentication for all other transactions.<\/li>\n<\/ol>\n<h3 id=\"scenario-3\">Scenario 3<\/h3>\n<p>After you have implemented the rule mentioned in scenario 2, you are still experiencing significant fraud in transactions above USD 200 in the US.<\/p>\n<p>One of the card schemes reached out to you that the number of Notifications of Fraud is becoming too high. As an emergency measure, you want to make sure that you always trigger a 3D Secure challenge to increase friction.<\/p>\n<p>Rules you should set up:<\/p>\n<ol>\n<li><a href=\"#configuring-dynamic-3d-secure-rules\">Dynamic 3D Secure rule<\/a>: When the amount is <strong>greater than USD 200<\/strong> AND the issuer country is <strong>United States<\/strong>, then <strong>Always<\/strong> request 3D Secure and <strong>Always<\/strong> request challenge.\n<div class=\"notices yellow\">\n<p>Setting request challenge to <strong>Always<\/strong> adds <a href=\"#request-3ds-challenge\">friction and can impact conversion negatively<\/a>. We recommend to use this in special circumstances only.<\/p>\n<\/div><\/li>\n<li><a href=\"#default-rules\">Default 3D Secure rule<\/a>: <strong>Prefer not<\/strong> to request 3D Secure authentication for all other transactions.<\/li>\n<\/ol>\n<h2 id=\"3ds-payment-request\">Override using the payment request<\/h2>\n<p>Instead of using Dynamic 3D Secure, you can include parameters in your payment request directly to influence when to use 3D Secure, and if it is, if the shopper should be challenged.<\/p>\n<div class=\"notices green\">\n<p>Parameters sent in the payment request override any Dynamic 3D Secure rules that you have configured.<\/p>\n<\/div>\n<p>Include the following fields in the payment request to:<\/p>\n<ul>\n<li>Request 3D Secure authentication:  <a href=\"https:\/\/docs.adyen.com\/api-explorer\/Checkout\/latest\/post\/payments#request-authenticationData-attemptAuthentication\" class=\"codeLabel  external-link no-image\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">authenticationData.attemptAuthentication<\/a>.<br \/>\nFor Checkout API v68 and earlier, use  <a href=\"https:\/\/docs.adyen.com\/api-explorer\/Checkout\/68\/post\/payments#request-additionalData-AdditionalData3DSecure-executeThreeD\" class=\"codeLabel  external-link no-image\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">executeThreeD<\/a>.<\/li>\n<li>Present a challenge:  <a href=\"https:\/\/docs.adyen.com\/api-explorer\/Checkout\/latest\/post\/payments#request-threeDS2RequestData-threeDSRequestorChallengeInd\" class=\"codeLabel  external-link no-image\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">threeDS2RequestData.threeDSRequestorChallengeInd<\/a>. This parameter will only be used if 3D Secure is requested.<br \/>\nFor Checkout API v67 or earlier, use  <a href=\"https:\/\/docs.adyen.com\/api-explorer\/Checkout\/67\/post\/payments#request-threeDS2RequestData-challengeIndicator\" class=\"codeLabel  external-link no-image\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">threeDS2RequestData.challengeIndicator<\/a>.<\/li>\n<\/ul>\n<h2 id=\"risk-based-authentication\">Risk-based authentication<\/h2>\n<p>Risk-based authentication for <a href=\"\/risk-management\/configure-your-risk-profile\/#new-profile-risk-rules\">Protect premium<\/a> complements the machine learning evaluation. You can save more transactions by sending them to 3D Secure and, as a result, further increase your conversion rate. Risk-based authentication increases authentication costs, but leads to more settled transactions and more revenue.<\/p>\n<p>Risk-based authentication sends transactions that would have been blocked by the machine learning fraud risk rule to 3D Secure 2. This way, legitimate transactions can be saved, and fraudsters can be stopped when they fail to authenticate.<\/p>\n<p>When the authentication is successful, the transaction is authorized, and there is a liability shift. When the 3D Secure challenge fails, the transaction stays blocked. If 3D Secure is not available, you will not be charged an authentication fee, and Protect reverts the transaction to a decline.<\/p>\n<p>You can view the impact of risk-based authentication in the <a href=\"\/risk-management\/configure-your-risk-profile#view-risk-profile-analytics\">risk profile analytics<\/a> section. You can enable or disable risk-based authentication in the <a href=\"\/risk-management\/configure-risk-settings\">risk settings<\/a>.<\/p>\n<p>When you open the <a href=\"\/risk-management\/configure-your-risk-profile#new-profile-results\">risk results<\/a> page for a transaction, you can identify if it went through risk-based authentication.<\/p>\n<h2 id=\"see-also\">See also<\/h2>\n<div class=\"see-also-links output-inline\" id=\"see-also\">\n<ul><li><a href=\"\/online-payments\/3d-secure\"\n                        target=\"_self\"\n                        >\n                    3D Secure integration guides\n                <\/a><\/li><li><a href=\"\/online-payments\/psd2-sca-compliance-and-implementation-guide\"\n                        target=\"_self\"\n                        >\n                    PSD2 SCA compliance and implementation guide\n                <\/a><\/li><li><a href=\"\/online-payments\/3d-secure-for-regulation-compliance\"\n                        target=\"_self\"\n                        >\n                    3D Secure for regulation compliance\n                <\/a><\/li><\/ul><\/div>\n","url":"https:\/\/docs.adyen.com\/risk-management\/dynamic-3d-secure","articleFields":{"description":"Set up rules to determine which card payments are routed through 3D Secure authentication, and if they should be challenged.","id":"24217646","type":"page","_expandable":{"operations":""},"status":"current","feedback_component":true,"last_edit_on":"08-03-2023 13:44","page_id":"c98c6b07-b0ef-4ec2-96fc-b2fb18689baa","filters_component":false,"decision_tree":"[]"},"algolia":{"url":"https:\/\/docs.adyen.com\/risk-management\/dynamic-3d-secure","title":"Dynamic 3D Secure","content":"When you support 3D Secure 2 in your website or mobile app, and send in a payment request, 3D Secure authentication can be triggered for the transaction. You can use the default 3D Secure rule and Dynamic 3D Secure rules to make sure 3D Secure is requested and, in special cases, to request a 3D Secure challenge.\nRequirements\nBefore you begin, take into account the following requirements and limitations.\n\n\n\nRequirement\nDescription\n\n\n\n\nIntegration type\nMake sure that you have built an online payments integration, and that you have implemented 3D Secure 2.\n\n\nCustomer Area roles\nTo add or change Dynamic 3D Secure rules, make sure that you have one of the following role(s): Merchant change risk settingsManagement Dynamic 3D Secure Rules\n\n\nLimitations\nTo use Dynamic 3D Secure in combination with risk management, risk must be enabled. Protect premium features must be enabled to: Use risk-based authentication.Create custom rules to link to Dynamic 3D Secure rules.\n\n\nSetup steps\nImplement 3D Secure 2. Then: To use Dynamic 3D Secure: Configure the default 3D Secure rule to specify your overall preferences.Configure Dynamic 3D Secure rules to create rules with more specific conditions.To override any Dynamic 3D Secure rules:Specify parameters in the payment request.\n\n\n\nHow Dynamic 3D Secure works\nTo ensure that you stay compliant, we always authenticate transactions with 3D Secure if this is required by regulations such as PSD2 or other market specific regulations. To mitigate any effects on conversion, we do not trigger 3D Secure for out-of-scope transactions, or when the issuing bank does not enforce 3D Secure. For transactions within the scope of PSD2, we also handle requesting exemptions.\nYou can use Dynamic 3D Secure to make sure 3D Secure is requested and, in special cases, to request a 3D Secure challenge. You can do this even if 3D Secure is not required by regulations or the issuer. This can be useful, for example, to make sure a liability shift takes place or to add more friction for high-risk transactions.\nYou can specify your 3D Secure preferences using Dynamic 3D Secure as follows:\n\nUse the default rule as the setting to indicate your general preference to request 3D Secure. You can set this to Prefer not or Always. When set to Prefer not, Adyen can still decide to send the payment through 3D Secure because the issuer requires it, to ensure compliance with regulations, or to improve conversion. When set to Always, we will always request 3D Secure on your behalf.\nCreate more specific Dynamic 3D Secure rules. You can set conditions to determine for which payments to request 3D Secure authentication, and if you prefer to request a 3D Secure challenge.\n\nAlternatively, you can include parameters in your payment request to specify when a transaction should go through 3D Secure 2. And, when you use Protect premium, you can also benefit from risk-based authentication. Risk-based authentication sends transactions that would have been blocked by the machine learning fraud risk rule to 3D Secure 2.\nDefault 3D Secure rule\nWhen you create a new company account or merchant account, the default rule is set to Prefer not.\nChoose from the following possible settings:\n\nAlways: Use 3D Secure whenever possible. With this rule, there will still be transactions that do not go through 3D Secure authentication, for example, when the issuer doesn't support 3D Secure yet, or when the card isn't enrolled.\nPrefer not: Do not apply 3D Secure authentication unless it is required by regulation or the issuer, or if it can help optimize performance.\n\nDynamic 3D Secure rules\nWhen you configure a Dynamic 3D Secure rule, you first specify the conditions to trigger the rule, and then you determine what happens when it triggers. When the rule triggers, you can specify what you want to do: request 3D Secure and request a challenge.\nRequest 3D Secure\nWhen you proactively request 3D Secure, you add an extra authentication layer to the payment flow. The transaction either goes through the challenge flow or the frictionless flow depending on the issuer.\nThis can reduce the risk of fraud because a transaction with a successful 3D Secure authentication will result in a liability shift. This way, you can use Dynamic 3D Secure rules to mitigate the risk for certain transactions.\nIt is important to understand that there is a trade-off. By requesting 3D Secure, you add friction. This friction impacts conversion because some shoppers might drop off. However, at the same time, if the authentication is successful, you reduce fraud and obtain a liability shift.\nRequest a challenge\nYou can set your preference to present a challenge even if the frictionless flow is available. Both a successful challenge flow and a successful frictionless flow result in a liability shift. By default, to optimize conversion, a transaction will use the frictionless flow if it is available.\nRequesting a challenge is a way to add more friction because it requires additional shopper interaction. We recommend that you only set your preference to always request a 3D Secure challenge in special circumstances. This because the challenge adds significant friction and could lead to a higher shopper drop-off rate. Use it, for example, when you are experiencing extremely high fraud rates and requesting 3D Secure alone does not help.\nConfigure a Dynamic 3D Secure rule\nThere are few things to keep in mind when configuring Dynamic 3D Secure rules:\n\nRules are evaluated in order, from first to last.\nIf a rule is triggered, the remaining rules are not evaluated.\nYou can configure rules on the company account, or on a merchant account. Rules configured on the merchant account have priority and only affect payments for that specific merchant account.\nWherever possible, create several simple rules instead of combining many logic points into a single rule.\nConsider each separate condition that you specify within the rule as an AND statement. The rule will trigger if both conditions are met. However, when you select multiple values within a condition, the rule will trigger when any of these values are true.\n\nTo configure a rule, in your Customer Area:\n\n\nGo to Revenue &amp; risk &gt; Dynamic 3D Secure.\n\n\nSelect Create new rule to make a new rule or select the name of the rule if you want to modify an existing rule.\n\n\nConfigure the criteria shown in the following table.\nYou can combine criteria to create nested rules. For example, you may decide to use 3D Secure for every transaction where the issuing card is from Mexico and the transaction value is above USD&nbsp;100.\nCriteriaDescription\nIssuer country\n\nThe country where the card was issued.\n\nShopper country\n\nThe country of the shopper, based on the IP address submitted with the payment.\n\nPayment method\n\nThe card type (for example, American Express, Visa Platinum, etc. For more information, see PaymentMethodVariant).\n\nDevice type\n\nThe type of device that submitted the transaction. You can indicate mobile, desktop, or tablet devices.The transaction must have device data submitted with it for this feature to work.\n\nAmount\n\nThe transaction value. When you configure this for a specific currency, the rule will automatically convert to other currencies. For example, a EUR\u00a020 rule will automatically trigger for the equivalent amount in GBP.\n\nRisk score\n\nDo not use this condition, it does not apply to Protect. The risk score condition was used in the classic risk engine to target transactions for 3D Secure when they met a certain risk score threshold.\n\nBIN and BIN Range\n\nThe first six digits on a credit card. This identifies the Issuing bank of the card. For more information, read Bank Identification Number (BIN). You can target a set or range of BINs, to use 3D Secure only for transactions from certain issuing banks.\n\nRisk check\n\nThe pre-authorization custom risk rule with the Check for 3DS action that you want use to trigger 3D Secure.\n\n\n\nFor each condition met, assign actions to request 3D Secure authentication, and your preference to present a challenge:\n\nRequest 3DS: If the condition is met, choose to apply any of the default 3D Secure rules (Prefer not or Always).\nRequest challenge: If you set up a rule where Request 3DS is set to Always, you also have the option to set your preference to request a challenge (Prefer not or Always).\n\nSetting request challenge to Always adds friction and can impact conversion negatively. We recommend to use this in special circumstances only.\n\n\n\n\nWhen you have created your rule, add a name for the rule and select Save. If you have updated an existing rule, also select Save.\n\n\nRules are applied in the order they appear in the list. To set your preferences, move the most important rule to the top of the list, and order the rest of the rules in the order that you want them to be applied in and select Save.\n\n\nExample scenarios\nThe following scenarios are some fictional examples to illustrate how you could set up Dynamic 3D Secure rules. You can create your own rules that follow your specific business needs and logic.\nScenario 1\nYou are planning on expanding your business in Canada. You have previously used 3D Secure in the UK (where conversion rates are high), and you want to avoid using 3D Secure in Canada. All your traffic is from the UK and Canada.\nRules you should set up:\n\nDynamic 3D Secure rule: When the issuer country is Canada, then Prefer not to request 3D Secure.\nDefault 3D Secure rule: Always request 3D Secure for all other transactions.\n\nOnly a Prefer not rule is needed since the default action is for transactions to use 3D Secure. With this setup, all UK transactions will use 3D Secure.\nScenario 2\nYou are experiencing significant fraud in transactions above USD 200 in the US. You want an extra layer of authentication for these payments and a liability shift.\nRules you should set up:\n\nDynamic 3D Secure rule: When the amount is greater than USD 200 AND the issuer country is United States, then Always request 3D Secure and Prefer not to request challenge.\nDefault 3D Secure rule: Prefer not to request 3D Secure authentication for all other transactions.\n\nScenario 3\nAfter you have implemented the rule mentioned in scenario 2, you are still experiencing significant fraud in transactions above USD 200 in the US.\nOne of the card schemes reached out to you that the number of Notifications of Fraud is becoming too high. As an emergency measure, you want to make sure that you always trigger a 3D Secure challenge to increase friction.\nRules you should set up:\n\nDynamic 3D Secure rule: When the amount is greater than USD 200 AND the issuer country is United States, then Always request 3D Secure and Always request challenge.\n\nSetting request challenge to Always adds friction and can impact conversion negatively. We recommend to use this in special circumstances only.\n\nDefault 3D Secure rule: Prefer not to request 3D Secure authentication for all other transactions.\n\nOverride using the payment request\nInstead of using Dynamic 3D Secure, you can include parameters in your payment request directly to influence when to use 3D Secure, and if it is, if the shopper should be challenged.\n\nParameters sent in the payment request override any Dynamic 3D Secure rules that you have configured.\n\nInclude the following fields in the payment request to:\n\nRequest 3D Secure authentication:  authenticationData.attemptAuthentication.\nFor Checkout API v68 and earlier, use  executeThreeD.\nPresent a challenge:  threeDS2RequestData.threeDSRequestorChallengeInd. This parameter will only be used if 3D Secure is requested.\nFor Checkout API v67 or earlier, use  threeDS2RequestData.challengeIndicator.\n\nRisk-based authentication\nRisk-based authentication for Protect premium complements the machine learning evaluation. You can save more transactions by sending them to 3D Secure and, as a result, further increase your conversion rate. Risk-based authentication increases authentication costs, but leads to more settled transactions and more revenue.\nRisk-based authentication sends transactions that would have been blocked by the machine learning fraud risk rule to 3D Secure 2. This way, legitimate transactions can be saved, and fraudsters can be stopped when they fail to authenticate.\nWhen the authentication is successful, the transaction is authorized, and there is a liability shift. When the 3D Secure challenge fails, the transaction stays blocked. If 3D Secure is not available, you will not be charged an authentication fee, and Protect reverts the transaction to a decline.\nYou can view the impact of risk-based authentication in the risk profile analytics section. You can enable or disable risk-based authentication in the risk settings.\nWhen you open the risk results page for a transaction, you can identify if it went through risk-based authentication.\nSee also\n\n\n                    3D Secure integration guides\n                \n                    PSD2 SCA compliance and implementation guide\n                \n                    3D Secure for regulation compliance\n                \n","type":"page","locale":"en","boost":18,"hierarchy":{"lvl0":"Home","lvl1":"Risk management","lvl2":"Dynamic 3D Secure"},"hierarchy_url":{"lvl0":"https:\/\/docs.adyen.com\/","lvl1":"https:\/\/docs.adyen.com\/risk-management","lvl2":"\/risk-management\/dynamic-3d-secure"},"levels":3,"category":"Risk Management","category_color":"green","tags":["Dynamic","Secure"]},"articleFiles":{"dynamic-3ds-sample-rule.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/10.risk-management\/15.dynamic-3d-secure\/dynamic-3ds-sample-rule.png\" \/>"}}
