IDP Support Center
  • Welcome
  • Getting started
    • What is IDP?
  • User Guide
    • User guide center
    • Get started with OXU
      • OXU Identity user guide
    • Account Management
      • Authentication
        • Sign up with Email and Password
        • Sign up with Google (optional)
        • Sign in with Email and Password
        • Google OIDC: Sign in to Google via OXU
        • Password requirements enforcement
        • Secure password hashing and storage
      • Account security
        • What should I do if I don't receive a verification code when signing up or forgot password?
        • Email verification
        • Two-Factor Authentication
          • Passkey authentication
          • 2FA-Email verification codes
          • MFA-Authenticator apps (TOTP)
          • MFA-Passkeys (FIDO2 / WebAuthn)
      • Data & Privacy
      • User Experience
        • Cross-platform web support
      • App Consent Management
    • Organization Admin App
      • Business Owner (Default Authority)
        • Organization Management
          • Organization creation
          • Domain ownership verification (DNS)
        • Organizational Structure
          • Organizational Units (OUs)
          • Workspaces
          • Hierarchical access scoping
        • Security & Governance
          • Enforced security policies
            • IP-Based access control
            • Geo-based access policies
            • Device and platform restrictions
          • Enforcing stronger authentication for risky login behavior
            • Risk Detection signals
            • Step-Up authentication
        • Roles & permissions
          • Assign role to user in Organization
          • Permissions list
      • SCIM – Automated user and workspace provisioning
        • What is SCIM used for?
        • User Lifecycle management
      • Administrator
        • Team & Access
          • Invite and manage users
          • Assign roles
          • Manage access at OU and Workspace level
            • Manage Access at Organizational Unit (OU)
            • Manage Workspace level
              • Team & Access – Members Management
        • Group management
        • Organization Unit
          • Create & manage Organization Units
          • Viewing and searching Organizational Units
          • Moving an Organizational Unit
          • Deleting an Organizational Unit
        • Manage activity logs of Organization's member
      • Become an OXU developer
      • App management - Workspace access
      • Report & Analytics Center
    • OXU Workspace
      • Guide to create workspace
      • Guide to manage workspace information
      • Guide to manage role and permissions
      • Applications
        • Guide to manage applications
        • OXU Developer
          • What is OXU developer
          • User guides
            • 1. Become OXU developer
            • 2. Create an app
            • 3. Input application info
              • About app ratings and reviews
            • 4. Config resource & security info
            • Security Best Practices
            • 5. Set up Pricing info
            • 6. Publish your app
              • Prepare before publishing your app
            • 7. Manage your app
              • App lifecycle
          • App versioning
        • OXU Store
          • What is OXU Store
          • 1. Register as an user
          • 2. Browsing & searching apps
          • 3. View app details
          • 4. Subscribe an app
            • Enable & Subscribe app for business workspace
          • 5. Manage subscriptions
          • 6. Rate & review an app
  • Support
    • Support center
      • What is Oten account & what can I do with Account Management App?
      • How to create account and password?
      • How to manage your Oten account information?
      • How to use MFA to protect your account?
      • What is WorkSpace & what can you do with WS?
      • What is Organization Admin app & what can you do with OAA?
    • Privacy Policy
    • Terms and conditions
      • Oten developer terms and conditions
      • Oten Store terms and conditions
    • FAQs
      • Store FAQs
      • Developer FAQ
    • Contact Us
  • Integration
    • Integration document
      • IDP integration
        • Environments: sandbox & production
        • Regular web application client
        • Native application client
        • Single page application client
        • SAML integration
        • Managing your integration applications
        • FAQ
      • What is SSO?
      • Why use SSO?
    • Provisioning connector
      • Google Workspace Configuration
    • Understand SSO flow
      • Overview
      • Flow Diagram
    • Developer Integration guide
      • Integration flow overview
    • Oten to OXU Migration guide
    • Prerequisites
      • Discovery Configuration
      • JAR Requirement - CRITICAL
      • JAR Complete Implementation Guide
      • PKCE Implementation Guide
        • Step 1: Choose OAuth Library
        • Step 2: Configure OAuth Client
        • Step 3: Implement Authorization Flow
        • Step 4: Handle Callback
        • Step 5: Token Management
      • Best practice
        • Security
      • Support & Troubleshoot
        • Common Errors
        • Debug and Troubleshooting
        • Contact Support
      • Appendix
        • Configuration Reference
        • Error Codes Reference
        • API Reference
        • Sample Code
        • Glossary
  • What's New
    • v1.0.29 - Aug 19, 2026
    • v1.0.28 - Aug 12, 2026
    • v1.0.27 - Aug 08, 2026
    • v1.0.26 - July 29 & 31, 2026
    • v1.0.25 - July 22, 2026
    • v1.0.24 - Jun 21, 2026
    • v1.0.23 - Jun 17, 2026
    • v1.0.22 - Jun 03, 2026
    • v1.0.21 - May 27, 2026
    • v1.0.20 - Apr 28, 2026
    • v1.0.19 - Apr 21, 2026
    • v1.0.18 - Apr 15, 2026
    • v1.0.17 - Apr 03, 2026
    • v1.0.16 - Mar 28, 2026
    • v1.0.15 - Mar 05 & 13, 2026
    • v1.0.14 - Feb 11, 2026
    • v1.0.13 - Jan 14, 2026
    • v1.0.12 - Jan 05, 2026
    • v1.0.11 - Jan 04, 2026
    • v1.0.10 - Dec 25, 2025
    • v1.0.9 - Dec 07, 2025
    • v1.0.8 - Nov 23, 2025
    • v1.0.7 - Nov 09, 2025
    • v1.0.6 - Oct 26, 2025
    • v1.0.5 - Sep 29, 2025
    • v1.0.4 - Sep 28, 2025
    • v1.0.3 - Sep 14, 2025
    • v1.0.2 - Aug 31, 2025
    • v1.0.1 - Aug 17, 2025
    • v1.0.0 - Aug 03, 2025
On this page
  1. User Guide
  2. Organization Admin App
  3. Business Owner (Default Authority)
  4. Security & Governance
  5. Enforced security policies

Geo-based access policies

PreviousIP-Based access controlNextDevice and platform restrictions

Last updated 6 months ago

  • I am new. Where should I start?
  • I already understand. How do I proceed step by step?
  • Result
  • Additional notes
  • Summary

I am new. Where should I start?

Purpose

Geo-based access control allows organizations to:

  • Restrict access by country or region

  • Allow access only from approved geographic locations

  • Block access from high-risk or restricted regions

  • Comply with regulatory, legal, or internal security requirements

This feature helps reduce security risks related to unauthorized or suspicious access from certain locations.


Prerequisites

Remember to check the following before configuration:

  • You have Admin or Security Management permissions

  • An Access Security policy can be created or edited

  • You know which countries or regions should be allowed or denied

  • Geo-location detection is enabled and supported by the system


I already understand. How do I proceed step by step?


  1. In the Access Security Rules section, select Add rule

  2. A new rule (for example, Rule 1) will appear


  1. Under the rule, select Add condition

  2. Choose Location (Country / Region)


Choose how geographic locations are evaluated:

Whitelist / Allow

  • Users from the selected countries or regions will have access

  • All other locations will be denied

Example:

  • Allow access only from Vietnam and Singapore

Blacklist / Deny

  • Users from the selected countries or regions will not have access

  • All other locations will be allowed

Example:

  • Deny access from restricted or high-risk countries (Cambodia,..)


  1. In the Country / Region field, select one or more locations

  2. Multiple countries or regions can be added based on policy needs



  1. Review all rules and conditions

  2. Select Create access security to activate the policy


  • User access is evaluated based on detected geographic location

  • Access is automatically allowed or denied based on policy configuration

  • Policies are enforced during sign-in and access attempts


  • Geo-location is determined using IP-based location data

  • VPNs or proxies may affect location accuracy

  • If Whitelist / Allow is used and no location matches, access is denied by default

  • If Blacklist / Deny is used, only selected locations are blocked

  • For stronger security, combine geo-based rules with MFA


  • Geo-based policies control access by country or region

  • Supports both allowlist and denylist strategies

  • Helps improve security and regulatory compliance

  • Works best when combined with other access security controls

Step 1: Create a New Access Security Policy

  • Profile Account → Admin

  • Welcome page Admin

  • Click on menu Security Policy → Access Security

  • Select Create new access security

  • Fill in the required fields:

  • (Optional) Add a Description to clarify the policy purpose

Step 2: Add an Access Security Rule

Step 3: Add Geo Location Condition

Step 4: Select Policy Mode

Step 5: Select country or region

Step 6: (Optional) Combine with Other Conditions

  • Select Add condition to combine geo-based rules with:

  • All conditions in the same rule are evaluated together

Step 7: Create Access security policy

Result

Additional notes

Summary

Sign in as an administrator :

  • Access security code

  • Access security name

IP or IP ranges

  • Device OS

  • Device compliance

  • Oten Admin | Security Policy & User management