Authentication policies in Yandex Identity Hub
Note
This feature is at the Preview stage.
In Yandex Identity Hub, authentication policies are used for granular management of user and user group access to Yandex Identity Hub applications by denying or allowing authentication based on the policy criteria.
Currently, authentication policies can only be managed in the Cloud Center UIorganization-manager.admin role or higher.
Policy scope
An authentication policy can apply to user authentication events based on the following condition types:
Note
The conditions specified in the policy are applied with the AND logic when checking whether the user can authenticate.
Users and user groups
You can configure an authentication policy to apply to all users in an Yandex Identity Hub organization, or to specific users or user groups.
You can also exclude specific users or user groups from the policy. Note that you cannot specify the same users or user groups simultaneously in both the inclusion and exclusion lists.
Applications
You can configure an authentication policy to apply to all applications created in an Yandex Identity Hub organization or to specific ones.
You can also exclude specific applications from the policy.
Networks and IP addresses
You can configure an authentication policy to apply to authentication from all possible IP addresses or to specific ranges of IPv4 or IPv6 addresses in CIDR
You can also exclude specific IP address ranges from the policy. Note that you cannot specify the same IP address ranges in both the inclusion and exclusion lists at the same time.
Policy-driven actions
Currently, authentication policies can deny user authentication if the authentication event matches the policy's defined conditions.
Policy statuses
The status of an authentication policy can be either Active or Inactive. Inactive policies are not applied to user authentication events.
Useful links
- Creating an authentication policy
- Activating/deactivating an authentication policy
- Editing an authentication policy
- Deleting an authentication policy
- Applications in Yandex Identity Hub
An organization is the highest resource in the Yandex Cloud resource model hierarchy that consolidates the resources of all other services. It is also used for user management as well as authentication and authorization management. For more information, see Organization.
You can group Yandex Identity Hub users to simplify access management in Yandex Cloud. For more information, see User groups.
Yandex Identity Hub SAML and OIDC applications allow Yandex Cloud users to authenticate in services of third-party service providers. For more information, see Applications in Yandex Identity Hub.
Yandex Cloud uses Yandex accounts as well as federated and local user accounts. For more information, see Accounts in Yandex Cloud.
The organization-manager.admin role enables managing organization settings, identity federations, user pools, SAML applications, OIDC applications, users and user groups, and users' access permissions to the organization and its resources. To learn more, see Access management in Yandex Identity Hub.