<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Users from Blocked Countries Able to Use Okta Verify
Multi-Factor Authentication
Okta Identity Engine
Overview

A user successfully enrolls in Okta Verify and authenticates from a country that the sign-on policies block. Users bypass these policies by using a VPN to appear inside an allowed network zone. Prevent this behavior by configuring an enrollment policy rule that denies authenticator enrollment for IP addresses outside the allowed zone.

Applies To
  • Okta Verify
  • Okta Identity Engine (OIE)
  • Blocked Country
Cause

A VPN masks the actual location of the user, making the connection appear to originate from an allowed network zone.

Solution

    How is Okta Verify enrollment restricted to specific network zones?

     

    Configure the authenticator enrollment policy to deny enrollment for users outside the allowed IP zone.

    1. Go to Authenticators > Enrollment and identify the applicable enrollment policy for the affected users.
    2. Edit the relevant rule intended for these users.
    3. Locate the User's IP is condition, choose Not in Zone, and specify the allowed IP zone.
    4. Select Deny enrollment of all authenticators.
      • Verify the configuration matches the provided example.

    Network  Zone Configuration Example

    Loading
    Users from Blocked Countries Able to Use Okta Verify