← Course Home
Okta Certified Administrator · Part II

Security Enforcement

23% of Part II — the final and most policy-heavy use case.

Security Enforcement

Task 3: Modify the Default Global Session Policy

5 tasks · this deck covers task 3 of 5

↑ Security Enforcement Overview

The Task

"Modify the default global sessions policy"

This concept already has a full deck in Part I's Security section. This task is the "actually go change it" version of that same content.

The Connection — Full Deck Already Exists

That deck covers what a global session policy actually controls, the default org-wide policy, and — critically — the LDAP interface gotcha (global session settings are disabled for LDAP-authenticated users, who instead use MFA credential syntax like password,123456).

The Operational Angle

"Modify the default" specifically means editing the org's built-in policy directly, rather than layering a new higher-priority rule on top of it. Every org has exactly one default policy — there's nothing to create here, only to change.

The Angle — What Trips People Up

Watch for this in your own sandbox run:

→ Changing the default policy and expecting it to affect LDAP-authenticated users — it won't, per the gotcha already covered in the full deck.

One Line To Remember

Modifying the default global session policy means editing the org's one built-in policy directly, not adding a new rule. Full mechanics (what it controls, the LDAP-interface exception) already live in Security Module 1, Sub 2 — go there for the deep dive.

Sources: help.okta.com — about-okta-sign-on-policies.htm (full deck: Security Module 1, Sub 2)