
Ron-SAICE.96466 (SAIC) asked a question.
We would like to know what a “read-only admin” account has access to beyond just the UD, and if there is any way to further restrict that access.
Then we want to know if the LDAP interface can also have sign in policies assigned to so that we can limit where LDAP requests come from.

Hello @Ron-SAICE.96466 (SAIC),
Thanks for posting.
The read-only administrators are unable to edit any data:
https://help.okta.com/en/prod/Content/Topics/Security/administrators-read-only-admin.htm
You can find more information related here:
https://help.okta.com/en/prod/Content/Topics/Security/administrators-read-only-admin.htm
Regarding the LDAP interface, authentication policies go through the Okta sign-on policy. When you create this policy you decide the groups it will be applied, which limits the requests:
https://help.okta.com/en/prod/Content/Topics/Directory/LDAP-interface-main.htm
Here is a document that will help you with the Policy implementation
:https://help.okta.com/en/prod/Content/Topics/Security/policies/configure-password-policies.htm
Let us know if this helps.
Regards,
Natalia
Okta Inc.