<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007Tg41XCAROkta Classic EngineMulti-Factor AuthenticationAnswered2026-04-01T09:00:20.000Z2022-03-01T21:00:43.000Z2022-03-07T15:23:20.000Z

wllqx (wllqx) asked a question.

Can Okta Verify MFA enforce a same state rule

This came from our IT partners concerned about security. In the US, if someone logs into Okta in one state and then approves an Okta Verify MFA push in another, can this behavior be detected and blocked? If not at the state level then maybe the country level?


  • Hello @wllqx (wllqx)​,

     

    Thank you for posting.

     

    Yes, Okta has a feature for denying access to users if they are outside the network zone that you want to provide them access to.

     

    A Network Zone is a security perimeter to limit or restrict access to a network based on a single IP address, one or more IP address ranges, or a list of geolocations. Network Zones are defined and maintained by admins who wish to improve and strengthen network security for their organization and users.

     

    Please check the following links with information:

     

    https://help.okta.com/en/prod/Content/Topics/Security/network/get-started.htm

     

    https://help.okta.com/en/prod/Content/Topics/Security/network/add-network-zone-signon-policy.htm

     

    Regards,

    Natalia

    Okta Inc.

     

     

    Expand Post
  • k5fuw (k5fuw)

    Consider that policy carefully if your company offers vpn access. Once users connect to the vpn, their browser connections to Okta will originate from wherever the vpn endpoint is located, but their Okta Verify connections will originate from where the user is located, which could be another state or country.

     

    While Natalia's answer was not wrong, it didn't really address your specific question. Okta does not have the ability to compare the location of the login and the location of the MFA response and then deny access if those are from different states or countries. If you configure a network zone to block a specific state or country, then Okta will block all connections from that location, whether it is a login or an MFA response.

    Expand Post
This question is closed.
Loading
Can Okta Verify MFA enforce a same state rule