Skip to main content

Okta Policies & Network Zones

Status: Scaffold — content in progress

Policy Types

PolicyControls
Sign-on policyWhich authenticators required per app, per group, per location
MFA enrollment policyWhich factors users can/must enroll
Password policyComplexity, rotation, lockout
Global session policySession lifetime, device trust

Network Zones

Okta Network Zones allow IP-based policy (allow/deny/require extra MFA from specific IPs).

Misconfiguration risk: Overly broad trusted zones allow bypass of MFA requirements.

TopicLink
Okta Overviewokta-overview
MFA Fatiguemfa-fatigue