Feature

Adaptive access policies

Apply extra control when the sign-in context looks different.

  • IP restrictions
  • Geography restrictions
  • Rate limiting and lockout
  • Per-application policies

What it does

Use context before allowing access

Restrict sign-in by network and geography so access can depend on where a request comes from, not only on the password.

Step up the sensitive paths

Pair contextual restrictions with multi-factor authentication for administrative accounts and higher-risk applications.

Slow down repeated attacks

Rate limiting and automatic lockout reduce the blast radius of repeated failed sign-in attempts.

Keep policies close to the app

Per-application access policies let one application be tighter than another without forcing every team into the same rule.

Setting it up

What the rollout looks like

Choose trusted networks

Define IP ranges that should be allowed or restricted.

Set geography rules

Decide whether sign-ins from selected regions should be blocked.

Require MFA where needed

Apply multi-factor authentication to sensitive users or applications.

Monitor the log

Review failed sign-ins and administrative changes centrally.

Questions about adaptive access policies

Is this adaptive MFA?

It covers the access-policy side: IP, geography, rate limiting, lockout and MFA enforcement. Avoid claiming device-risk scoring unless it is confirmed in the product.

One sign-in for every app your team uses.

Set up your organisation, connect your directory and give your people a single secure launchpad.