This article provides steps to create a Dynamic Zone and apply it to an existing app sign-in policy rule to restrict application access to a specific country.
- Dynamic Zones
- Authentication Policies
- App Sign-in Policies
- Okta Identity Engine (OIE)
-
Navigate to Security > Networks.
-
Select Add Zone > Dynamic Zone.
-
Enter a name for the new zone.
-
In the Locations field, select the appropriate country to allow.
-
Select Save.
-
Navigate to Security > Authentication Policies.
-
Locate and select the app sign in policy that applies to the desired application.
-
Find the relevant rule within the policy and select the Edit option.
-
In the IF condition section, locate the And User's IP is dropdown menu and select the newly created Dynamic Zone.
- Click Save.
- Ensure all rules below this rule are set to DENY access.
-
Verify that users have the intended access based on the new policy rule.
