Application Sign-On Policy Risk Level Denies User Access
Last Updated:
Overview
This article addresses an issue where a user is denied access to an application. Although the user has the same configuration as other users who can access the application, they are blocked by an Application Sign-On Policy that evaluates their risk level.
Applies To
- Application Sign-On Policy
Cause
The user is assigned a high risk level because the user has no successful authentication history in the organization. The Application Sign-On Policy contains a rule that grants access based on a password-only factor for users with a low risk level.
Because the user is identified as high risk, they are not evaluated against the intended password-only rule. Instead, they are evaluated against a subsequent, stricter rule that requires a password plus an additional authentication factor. The user is not enrolled in a second factor and is, therefore, denied access.
Solution
-
Temporarily modify the Application Sign-On Policy to allow the user to authenticate successfully. This can be done by adding a temporary rule that specifically grants access to the user for their initial sign-in.
-
Instruct the user to sign in. A successful sign-in creates an authentication history.
-
Once a successful authentication event is recorded, the user's risk level is recalculated and changes from High to Low.
-
Remove the temporary rule from the Application Sign-On Policy. The user will now be correctly evaluated by the intended policy rule for low-risk users.
