<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006vxiijCAAOkta Classic EngineAdministrationAnswered2021-04-24T00:46:52.000Z2021-04-21T00:15:28.000Z2021-04-24T00:46:52.000Z
  • User16003423933115043497 (MFA and Devices)

    Hi Greg! Thank you for reaching out.

     

    If your use case is to have a set of countries be the allowed list, and others to require to be added to a whitelist, the best approach is to create two zones. One will be for your allowed countries, the second one will be for exceptions (whitelisting).

     

    This is applied by your Sign On Policy. That is where the network zones created kick in. From the Admin UI, go to Security, Authentication, Sign On and see the policy that is applied to everyone. Add a new rule and select "If user's IP is In Zone", then add your two Geolocation Zones you created, and allow access.

    At this stage, you should be able to add countries to your second zone for white listing, users in the first zone will automatically be allowed in and users not in the zone will be denied.

     

    Hope this helps! Have a great one!

     

    Radu Dutu

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
This question is closed.
Loading
Geolocation & IP Zone