23% of Part II — the final and most policy-heavy use case.
5 tasks · this deck covers task 3 of 5
↑ Security Enforcement OverviewThis concept already has a full deck in Part I's Security section. This task is the "actually go change it" version of that same content.
That deck covers what a global session policy actually controls, the default org-wide policy, and — critically — the LDAP interface gotcha (global session settings are disabled for LDAP-authenticated users, who instead use MFA credential syntax like password,123456).
"Modify the default" specifically means editing the org's built-in policy directly, rather than layering a new higher-priority rule on top of it. Every org has exactly one default policy — there's nothing to create here, only to change.
Watch for this in your own sandbox run:
→ Changing the default policy and expecting it to affect LDAP-authenticated users — it won't, per the gotcha already covered in the full deck.
Sources: help.okta.com — about-okta-sign-on-policies.htm (full deck: Security Module 1, Sub 2)
Next: Task 4 →