Remediation
Enforce MFA from Oracle Cloud Consoleβ
- Sign in to the OCI Console.
- Open the navigation menu and select
Identity & Security. - Under
Identity, selectDomains. - Select the identity domain that contains the affected users.
- Open
Security, then selectSign-on policies. - If
Security Policy for OCI Consoleexists, open it and confirm that:- The policy is activated.
- The OCI Console application is assigned to the policy.
- The
MFA for all usersrule is active. - The rule allows access, prompts for an additional factor, and sets MFA enrollment to
Required.
- If the
Security Policy for OCI Consolepolicy does not exist or cannot be used, create a sign-on policy for OCI Console access:- Select
Create sign-on policy. - Add a sign-on rule for the users or groups that require OCI Console access.
- Set the rule action to allow access.
- Enable
Prompt for an additional factor. - Set MFA enrollment to
Required. - Add the OCI Console application to the policy.
- Activate the policy after testing.
- Select
- Keep any temporary administrator exclusion limited to rollout or emergency-access testing, and remove it after MFA enforcement is verified.
- Have affected users complete MFA enrollment at their next OCI Console sign-in, then confirm their MFA status changes to
Activated.
User enrollmentβ
After MFA is enforced, users are prompted to enroll when they sign in to the OCI Console. Each user must register an approved factor, such as Oracle Mobile Authenticator or another factor allowed by the identity domain MFA settings. Administrators can disable MFA for another user during account recovery, but MFA activation is completed by the user.