
wllqx (wllqx) asked a question.
This came from our IT partners concerned about security. In the US, if someone logs into Okta in one state and then approves an Okta Verify MFA push in another, can this behavior be detected and blocked? If not at the state level then maybe the country level?

Hello @wllqx (wllqx),
Thank you for posting.
Yes, Okta has a feature for denying access to users if they are outside the network zone that you want to provide them access to.
A Network Zone is a security perimeter to limit or restrict access to a network based on a single IP address, one or more IP address ranges, or a list of geolocations. Network Zones are defined and maintained by admins who wish to improve and strengthen network security for their organization and users.
Please check the following links with information:
https://help.okta.com/en/prod/Content/Topics/Security/network/get-started.htm
https://help.okta.com/en/prod/Content/Topics/Security/network/add-network-zone-signon-policy.htm
Regards,
Natalia
Okta Inc.
Consider that policy carefully if your company offers vpn access. Once users connect to the vpn, their browser connections to Okta will originate from wherever the vpn endpoint is located, but their Okta Verify connections will originate from where the user is located, which could be another state or country.
While Natalia's answer was not wrong, it didn't really address your specific question. Okta does not have the ability to compare the location of the login and the location of the MFA response and then deny access if those are from different states or countries. If you configure a network zone to block a specific state or country, then Okta will block all connections from that location, whether it is a login or an MFA response.