Tenancies Without Identity Domains and Without the "Security Policy for OCI Console" Sign-On Policy

If you're using multifactor authentication (MFA) in tenancies without identity domains and without the "Security Policy for OCI Console" sign-on policy, and Oracle Identity Cloud Service as an auto-federated identity provider (IdP) in IAM, we recommend that you set up MFA using the following Oracle best practices.

To set up MFA without identity domains:

  1. Read Prerequisites.
  2. Enable MFA. See Step 1: Enable MFA Without Identity Domains.
  3. Create a sign-on policy. See Step 2: Create a New Sign-On Policy.

Prerequisites

Before you begin: Before you configure MFA, complete the following prerequisites.

  1. Review the MFA factors. The MFA factors available to you depend on the License Type you have. The License Type shows in the top right of the Identity Cloud Service console. See About Oracle Identity Cloud Service Pricing Models for more information about MFA and license types.
  2. Review the documentation for Use the Oracle Mobile Authenticator App as an Authentication Method to learn how to use Mobile app notification and Mobile app passcode in the Oracle Mobile Authenticator app.
  3. Optionally, and only during the roll out period, exclude an identity domain administrator from the "Security Policy for OCI Console" policy, so if you make any mistakes during roll out you have not locked yourself out of the Console.

    As soon as roll out is complete, and you are confident that your users have all set up MFA and can access the Console, you can remove this user account.

  4. Identify any Identity Cloud Service groups mapped to OCI IAM groups.
  5. Register a client application with an Identity Domain Administrator role to enable access to your identity domain using the REST API in case your Sign-On Policy configuration locks you out. If you don't register this client application and a Sign-On Policy configuration restricts access to everyone, then all users are locked out of the identity domain until you contact Oracle Support. For information about registering a Client Application, see Register a Client Application in Using the Oracle Identity Cloud Service REST APIs with Postman.
  6. Create a bypass code and store that code in a secure location. See Generate and Use the Bypass Code.