<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008OdLqfCAFOkta Classic EngineAuthenticationAnswered2025-10-11T09:01:02.000Z2022-11-15T21:04:20.000Z2022-11-16T06:31:02.000Z

hsdso (hsdso) asked a question.

Dedicated authentication policy for users that are traveling for business

We have a few users that are traveling most of the time. They use Okta for authentication and I am looking to see if there are any options to add another layer of security like "Specific Policy for Travelers" or add second authentication "SMS or Call".

Please advise.


  • flz9z (flz9z)

    Hi James Karimi ,

    You can add specific policy for these particular users and can enable additional MFA factors or you can use behavior detection for this users.

  • DonF.81354 (Customer)

    Yes, great question.

     

    Best way to do this would be to create a group specifically like “Traveler Group” and then you can create an Sign-On policy that applies to that group (just pay close attention to the order of the Sign-On policies). From here, the sky is the limit, much like Riya also stated. For instance, you can require certain MFA factors, how long sessions might last, risk levels, or additional behavior detection methods. Furthermore, you can dictate how often users must authentication with an MFA factor.

     

    You can also incorporate network zones into this as well. Perhaps you only want these traveling employees to connect if they are doing so via VPN, which can also be enforced here as well.

     

    Thanks!

    Expand Post
This question is closed.
Loading
Dedicated authentication policy for users that are traveling for business