Conditional access questions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
โ09-09-2022 05:28 AM
Hello
I have been reviewing the online material, but I can't find the answer to these questions: (I don't have admin access so may not be able to see all the screens ... I also tried the online simulations)
Can we have two levels of MFA? One for managed devices and one for unmanaged devices? I would want unmanaged devices (e.g., consultants) to have to MFA more often than folks on managed laptops.(e.g: Daily vs every few days)
For Geolocation. We would create a rule to allow 15 countries and block the rest. Once that is implemented, can we create a second rule to limit all unmanaged devices to North America? (hence only managed devices can login from the whole 15 countries identified)
Thanks for any input
- Labels:
-
Policies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
โ09-11-2022 01:43 PM
Should I assume this is not possible? ๐
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
โ09-12-2022 04:02 PM
@SlimJim checking on that for you.
Like someone's post? Give them a kudo!
Did someone's answer help you? Please mark it as a solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
โ09-12-2022 04:23 PM
@SlimJim Right now we don't support multiple levels of MFA, where you can specify triggering MFA based on duration of their last successful mfa attempt
You can create a rule that can have 1 or more conditions for user portal and SSO app access, so you can have a condition that specify managed device and a location (you can multiple countries)
![](/skins/images/C210B62239BAF37B0AB0FAEB086BB5F1/responsive_peak/images/icon_anonymous_message.png)
![](/skins/images/C210B62239BAF37B0AB0FAEB086BB5F1/responsive_peak/images/icon_anonymous_message.png)