Access policies

We can use access policies to perform step-up and reauthentication during a single sign-on flow based on contextual information. Access policies can be enforced at a federation or at API Protection for OAuth and OpenID Connect. Access policies are defined as JavaScript. Example scenarios:

Access policies can take contextual information as input:

Based on the contextual information, the administrator can choose from the following actions:

After an access policy is defined, it can be applied, used, and enforced on the following types of deployments.

Access policies cannot be applied or used by the following deployments.

For information, see Create an access policy.


Parent topic: Global settings