Security policy
A security policy controls which principals are granted privileged access to one or more resources. You can create the following types of policies:
-
Default: Applies to servers, secrets, SaaS app service accounts, Active Directory accounts, and database accounts. Default policies can grant access through Direct principals, which uses traditional selection, or Assignments, which uses relationship-based access control (Early Access).
-
Okta service accounts: Applies to Okta user accounts that are managed as service accounts.
As a security admin, you create a policy, assign principals to the policy, and add one or more rules. When creating a rule, you can establish specific conditions that users must meet to access a resource that's safeguarded by Okta Privileged Access. These rules can be customized for different resources by stacking or adding them until they cover all the privileged access needed for the set of principals. By doing this, you can set different controls over different resources to ensure that only authorized users can access them.
You can assign security administration to groups assigned as delegated security admins. The delegated security admins can then create policies that apply to resource groups for which they're the security owners. Security policies written by delegated security admins only apply to the resource group that they selected when creating the policy. See Add delegated security admin.
Before you begin
- Ensure that you're signed in to Okta Privileged Access.
-
You must have the Okta Privileged Access security admin role for the Default policy type.
-
The policy for Okta service accounts requires the user to have the Okta Privileged Access security admin role and the super admin role.
-
Review Security policy concepts.
-
Learn how multiple authentication and authorization conditions affect user access. See Rule conditions.
-
If you plan to create an assignments policy (Early Access), you must first create at least one relationship and one assignment. See Relationships and assignments overview for the complete workflow.
Create or update a security policy
To create a policy, you need to add a policy name, select how access is granted (Direct principals or Assignments), and create rules that apply to the principals or relationships. After you create the policy, you must publish it. A policy doesn't have any effect until it's published.
Create a default policy
Use the default option to create policies for servers, secrets, SaaS app accounts, Active Directory accounts, or database accounts.
-
Go to .
- Click Create policy, and then select Default.
- Enter a policy name and description.
-
Delegate policy administration by selecting one of the following options:
-
All resource groups. This allows policy rules to include resources that span across resource groups.
-
Specific resource groups. This allows policy rules to include only resources within the selected resource group. This setting also enables delegated security admins to manage this policy.
If you select this option, click the dropdown menu and select a resource group.
-
-
In the How access is granted section, select one of the following options:
- Assignments: Targets relationships and assignments instead of individual principals. Use this approach for relationship-based access control at scale. See Relationships and assignments overview for more information.
-
Direct principals: Targets specific principals (users, groups, and workload roles) directly. Use this approach when you need precise control over which individuals or teams have access to specific resources.
-
If you selected Assignments, click Select relationships, and then select one or more relationships. You can select up to 50 relationships per policy.
-
If you selected Direct principals, complete the following:
-
Click the Select Groups dropdown menu, and then select one or more groups.
- Click the Select users dropdown menu, and then select on or more users.
-
Click the Select Workload roles dropdown menu, and then select one or more workload role.
-
-
Click Add rule, and then configure the rule settings. See Add rules for a default policy for instructions.
- Click Save policy. You can now publish this policy.
Create a policy for Okta service accounts
Use this policy for Okta privileged accounts.
-
Go to .
- Click Create policy, and then select Okta privileged account.
- Enter a policy name and description.
-
Delegate policy administration by selecting one of the following options:
-
All resource groups
-
Specific resource groups. If you select this option, click the dropdown menu and select a resource group.
-
-
Click Add Principals, or click the edit icon (pencil) to update.
-
Select one or more groups that you want to add or modify, and then click Save.
-
Click Add rule, and then configure the rule settings. See Add rules for Okta service account policy for instructions.
-
Click Save. You can now publish this policy.
Publish a policy
After a policy is created it must be published.
When a published policy is changed, the changes are applied immediately without the need to publish the policy again.
-
Go to .
- On the policy you want to publish, click Actions.
- Click Publish to grant access to the policy.
Clone a policy
Security admins can clone an existing policy instead of creating an entirely new policy from scratch.
-
Go to .
- On the policy you want to clone, click Actions.
- Select Clone.
- Click Save Policy.