Understanding Okta Default Policies and Catch-All Rules
Last Updated:
Overview
Okta provides a required default policy for each policy type to ensure a policy applies to a user in all situations. This default policy acts as a catch-all rule that allows access if the user satisfies primary authentication, preventing Okta from locking out legitimate administrators and users while administrators configure the organization. Okta sign-on policies specify actions to allow access, such as prompting for a challenge and setting the time before prompting again.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Default Policy
- Sign-On Policies
Solution
Okta default policies possess specific characteristics and priority orders.
Okta provides one default policy for each policy type, named Default. It is a required policy that applies to new applications by default or any users for whom other policies in the Okta organization do not apply. This ensures that there is always a policy to apply to a user in all situations.
The Okta default policy possesses several specific characteristics regarding priority and deletion.
- Administrators cannot delete the required default policy.
- The default policy is always the last policy in the priority order. Any added policies of this type have higher priority than the default policy.
- The default policy always has one default rule that administrators cannot delete. It is always the last rule in the priority order. New rules added to the default policy have a higher priority than the default rule.
How does the default catch-all rule function in Okta Identity Engine?
Okta Identity Engine (OIE) allows administrators to vary authentication flows to applications based on group membership, device management, device posture, network zones, risk evaluation, user behavior, and more.
If an access request does not match any of the rules, it usually falls to the Default Catch-All rule. In most scenarios, the default catch-all rule allows access if the user satisfies primary authentication, such as a password or access to an email inbox. This is the default setting to avoid locking legitimate administrators and users out while administrators configure the organization.
