Restrict Specific Country Access to an Okta Application Using Dynamic Zones and App Sign-In Policies
Last Updated:
Overview
Security requirements often dictate restricting application access to users from specific countries. Administrators create a Dynamic Zone specifying the allowed or blocked countries and apply it to an existing application sign-in policy rule to enforce these geographical restrictions.
Applies To
- Okta Identity Engine (OIE)
- Dynamic Zones
- Authentication Policies
- App Sign-in Policies
Solution
How does Okta use a Dynamic Zone to restrict country access?
Navigate to the network security settings in the Admin Console to create a new Dynamic Zone and select the appropriate countries to allow or block.
- Navigate to Security > Networks.
- Select Add Zone > Dynamic Zone.
- Enter a name for the new zone.
- In the Locations field, select the appropriate country to allow.
- Select Save.
How does Okta use an authentication policy that requires the Dynamic Zone to enforce the restriction?
Locate the relevant application sign-in policy in the Admin Console, edit the rule conditions to require the newly created Dynamic Zone, and ensure subsequent rules deny access.
- Navigate to Security > Authentication Policies.
- Locate and select the app sign-in policy that applies to the desired application.
- Find the relevant rule within the policy and select Edit.
- In the IF condition section, locate the And User's IP is dropdown menu and select the newly created Dynamic Zone.
- Select Save.
- Ensure all rules below this rule are set to DENY access.
- Verify that users have the intended access based on the new policy rule.
