Policies Page

Policies

Notion image

This menu allows you to set custom policies for SSO Reset Frequencies, IP restrictions & Local account password length for your Evo instance

Policies are a great way to restrict access or define temporary single sign-on requirements.  These "Rules" will only apply to your SAML enabled web applications that have been integrated with Evo.

When applying a rule, it is applied globally, and will apply to all clients and users.

There are currently Five categories of rules available.

  1. Blocking IP Addresses allows you to restrict where log in attempts originate from.
    1. By Country allows you to pick from a list of countries and territories to block.
    2. Custom allows you to enter a single public IP address, or a block of public IP addresses you’d like to block.
  1. Single Sign-On (SSO) allows you to control a temporary duration for SSO before the user must re-authenticate. Or enforce multi-factor authentication (MFA) for all logins.
  1. Local Account Password Length allows you to set the password length amongst local accounts.
  1. Session Management lets you control how long before the session timeouts and requires re-authenticates as well as retention of sessions.
  1. Allowed Authentication Methods lets you control per tenant which Authentication methods are allowed
 

NOTE: Policies apply globally to all users/customers within your Evo Environment and are specific for SAML Web Apps. (Does not apply to Evo Credential Provider)

A policy for single sign-on can help you control a temporary duration for SSO before the user must re-authenticate or enforce multi-factor authentication (MFA) for all logins.

How do I add a rule for single sign-on (SSO) expiration?

NOTE: The SSO rule applies globally to all users/customers within your Evo Environment. SSO rule is specific for SAML Webapps. (Does not apply to Evo Credential Provider). Only 1 SSO rule is allowed per environment.

How to apply the rule globally

  1. From the dashboard, click Policies.
  1. Click the Add New Policy.
  1. Click Single Sign-On (SSO) Reset Frequency.
  1. Use the slider to define the rule.
    1. To Always Require MFA. Move the slider all the way to the left.
    2. To expire SSO after a period. Move the slider based on your organizations’ rules. Anywhere between 1 to 7 days.

How to edit a rule

  1. From the dashboard, click Policies.
  1. In the displayed list of rules, find the one you want to edit and select the pencil icon on the right
  1. Make the edits you want.
  1. Click Save Changes.

How to delete a rule

  1. From the dashboard, click Policies.
  1. In the displayed list of rules, find the one you want to delete and click the checkbox in the first column.
  1. From the Action menu at the bottom, select Delete.

When defining a policy, you can specify a single IP address or a range of IP addresses to apply globally.

When creating a policy to block a large range of IP addresses, it might be advantageous to explore the reason that so many exclusions are being made.

Creating a policy to block a country, rather than a ranges of IP address, might better suit your needs.

  • *Blocking a country will block the entire country, no exceptions allowed.

NOTE: This policy will apply globally to all users/customers within your Evo Environment. This policy is specific for SAML Webapps.(Does not apply to Evo Credential Provider).

How do I block IP addresses / countries for SAML integrations?

How to apply the rule globally

  1. From the dashboard, click Policies.
  1. Click the Add New Policy button.
  1. Click Block IP Addresses - Custom.
  1. Enter the single public IP Address or the range of public IP Addresses you’d like to block. When entering an IP address range, it must be entered as X.X.X.X - X.X.X.X.
  1. Click Apply. If after applying the IP addresses to the rule, you’ve found one that is incorrect or shouldn’t have been included. You can remove the address in question.
    1. To remove: Click the trash can next to the IP address.
  1. Repeat steps 6 & 7 for each IP address or range to be included in the rule.
  1. Once all IP address have been added and confirmed as correct, click Add Rule.

Country Based Policy

When defining a Country based policy, you can select a single country/territory, or multiple countries/territories to block.

Blocking a country/territory will block the entire region, no exceptions allowed.

NOTE: This policy will apply globally to all users/customers within your Evo Environment. This policy is specific for SAML Webapps.

How to apply the rule by Country

  1. From the dashboard, click Policies.
  1. Click the Add New Policy.
  1. Click Block IP Addresses – By Country.
  1. From the list of countries check the box to the left for each country to be blocked. To locate a specific country, use the search field to narrow down the list. Once all countries have been checked, click Add Rule.
Did this answer your question?
😞
😐
🤩