<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
iCloud Private Relay Authentication is Blocked by Dynamic Network Zone
Okta Classic Engine
Okta Identity Engine
Network Zones
Overview

When an Enhanced Dynamic Network Zone is configured to block ALL_ANONYMIZERS, users with Apple iCloud Relay Proxy enabled will receive the following error:

 

403 Forbidden

 

Applies To
  • Enhanced Dynamic Network Zone
  • iCloud Private Relay Proxy
Cause

Okta is blocking ALL_ANONYMIZERS, which includes APPLE_ICLOUD_RELAY_PROXY, causing the clients to meet the criteria to be blocked by the Enhanced Dynamic Network Zone condition.

Solution

Deactivate the DefaultEnhancedDynamicZone

  1. In the Admin Console, go to Security > Networks.
  2. Navigate to the DefaultEnhancedDynamicZone.

DefaultEnhancedDynamicZone

  1. Click Active, then click Inactive to deactivate the zone.

DefaultEnhancedDynamicZone

 

Create an Exception for the iCloud Relay Proxy

  1. In the Admin Console, go to Security > Networks.
  2. Select Add zone > Enhanced Dynamic Zone.  

Networks

  1. Enter a Zone name.

  2. Select Block access from IPs matching conditions to block the IP service category, locations, and ASNs in the zone.

Add Enhanced Dynamic Zone   

  1. Select All IP service categories except and enter APPLE_ICLOUD_RELAY_PROXY.

Add Enhanced Dynamic Zone    

    • Include locations: The locations selected in the next step are included in the zone.
      • If the option is left as None, then all locations are considered to be within this dynamic zone.
    • All locations except: The locations selected in the next step are excluded from the zone. All other locations are included.
      • In the Location field, enter the country, state, or region, if applicable.
      • Click Add Another to add more locations.  
  1. In the ISP autonomous system numbers (ASNs) field, enter the ASNs that must be included in the zone.
  2. Click Save.
  1. Set the network zone to Active.

 

Related References

Loading
iCloud Private Relay Authentication is Blocked by Dynamic Network Zone