<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006gyidxSAAOkta Classic EngineMulti-Factor AuthenticationAnswered2019-10-24T18:44:01.000Z2019-09-26T22:57:57.000Z2019-10-24T18:44:01.000Z
  • Hi Seth,

     

    Sergiu from Okta Support here. From what I've just tested this is due to the Risk which is currently set, as it stands it seems that if you setup a risk in a deny policy access cannot be created.

    I've enabled the risk in my own prev environment and tried to setup a deny policy and got this message "At this time, access cannot be denied if a risk score condition is selected."

     

    Being that this is still an EA feature I am unsure if using risk will allow you to deny access in the future but I am thinking that the logic behind it would be to not create a rule and for some reason a login will be flagged with a high risk and login would be denied.

    I think that the risk feature is leaning more towards if the risk is high then you can set up conditions for MFA rather than denying access. I hope this helps.

    Expand Post
    Selected as Best
  • Hi Seth,

     

    Sergiu from Okta Support here. From what I've just tested this is due to the Risk which is currently set, as it stands it seems that if you setup a risk in a deny policy access cannot be created.

    I've enabled the risk in my own prev environment and tried to setup a deny policy and got this message "At this time, access cannot be denied if a risk score condition is selected."

     

    Being that this is still an EA feature I am unsure if using risk will allow you to deny access in the future but I am thinking that the logic behind it would be to not create a rule and for some reason a login will be flagged with a high risk and login would be denied.

    I think that the risk feature is leaning more towards if the risk is high then you can set up conditions for MFA rather than denying access. I hope this helps.

    Expand Post
    Selected as Best
This question is closed.
Loading
Unable to denied logon based only on Risk