Editing an access policy
After creating a policy, you can review your setting and make changes before you publish your policy.
About this task
Procedure
-
Select Security > Access policies.
A table lists the available policies. The
icon indicates that the policy can be deleted. A lock icon
indicates that the policy is preset and can't be modified or deleted. -
Click the name of the policy that you want to edit.
The policy is displayed and the Details panel lists the ID, creation date, creator, last modifier, last modification date, and version.
-
Click the
icon.
- Optional:
Click the
icon to edit the Basic settings.
- Change the policy name.
- Add a description that provides information about the policy.
- Click Save.
- For native app policies, you can edit or add first contact rules.
-
Select whether to enable or disable Adaptive access.
For information about Adaptive access, see Managing adaptive access.Note: This option is not available for Native custom app policies.
-
Select the action that is taken for each level of risk. For MFA actions, you can choose one ore more of the following methods that are based on the tenant authentication factor configuration.
- Any available method (default)
- Duo Security
- Email OTP
- FIDO2
- SMS OTP
- Time-based OTP
- IBM Verify
- Voice OTP
- Select whether to send notifications to the user.
-
Select the action that is taken for each level of risk. For MFA actions, you can choose one ore more of the following methods that are based on the tenant authentication factor configuration.
-
Select whether to require multi-factor reauthentication.
-
Click the
icon to edit the reauthentication settings.
- Select the Require multi-factor reauthentication checkbox.
- Select the duration that the authentication remains valid. After that time expires, the user must authenticate again. The default setting is for 8 hours.
- You can specify whether you want reauthentication to apply to each of the user's devices.
-
Select the methods for reauthentication.
For MFA methods, you can specify to use any available method or choose one or more of the following methods that are based on the tenant authentication factor configuration.
- Any available method (default)
- Duo Security
- Behavioral biometrics
- Email OTP
- FIDO2
- SMS OTP
- Time-based OTP
- IBM Verify
- Voice OTP
- Click Save.
-
Click the
-
Add, edit, or delete post-authentication rules.
For information about rules, see Managing policy rules.
- Click Add rule.
- Specify a name for the rule.
- Optional: Add a description for the rule.
- Click Next.
-
Select the condition type, attribute, operator, and value.
Repeat these steps for each condition that you want to add.
- Click Next.
- Select the action to be taken when the rule conditions are met.
-
Specify the multi-factor authentication method.
Use any available method or choose one or more of the following methods that are based on the tenant authentication factor configuration.
- Any available method (default)
- Duo Security
- Behavioral biometrics
- Email OTP
- FIDO2
- SMS OTP
- Time-based OTP
- IBM Verify
- Voice OTP
- Click Add rule.
- Optional:
From the Policy rules section, you can use the
and
icons to sequence the order that the rules are evaluated.
The evaluation occurs in descending order. The default rule is always last in the sequence. -
If you do not need to make more changes, click Save draft.
The Publish button becomes enabled.
- If your changes are complete, click Publish to make the policy available to be assigned to applications.