23% of Part II — the final and most policy-heavy use case.
5 tasks · this deck covers task 4 of 5
↑ Security Enforcement OverviewThis is the app-level layer — distinct from the global session policy (Task 3). An authentication policy (also called an app sign-on policy) is what governs a specific application.
"App sign-in policies define how a user must authenticate to gain access to an app." They check conditions like group membership, IP location, and risk assessment before granting access.
Beyond app access itself, account management policies control authentication requirements during authenticator enrollment/un-enrollment, password recovery, and account unlocking — related but separate scenarios from the app sign-in policy itself.
Watch for this in your own sandbox run:
→ Building a brand-new policy from scratch when a preset already fits the need — check presets first.
→ Confusing an app sign-in policy with an account management policy — enrollment/recovery/unlock scenarios are governed separately.
Sources: help.okta.com — about-app-sign-on-policies.htm
Next: Task 5 →