Article 11 – Multifactor Authentication (MFA), Password Policies, and Risk-Based Sign-On Rules

1. Introduction to Authentication Hardening

Securing administrative access to Oracle Cloud Infrastructure (OCI) requires robust authentication controls. Credential compromise remains a primary attack vector targeting enterprise cloud environments.

OCI Identity Domains provide native Multifactor Authentication (MFA), customizable Password Policies, and Adaptive Risk-Based Sign-On Rules.

These tools allow security administrators to enforce strong authentication factors (such as FIDO2 hardware keys or TOTP authenticators) and dynamically evaluate session risk based on client IP, geographic location, and device context.

2. Supported Authentication Factors

OCI Identity Domains support multiple authentication factors:

  1. FIDO2 / WebAuthn Hardware Keys: The highest security factor (e.g., YubiKey, TouchID, Windows Hello). Resistant to phishing and man-in-the-middle attacks.
  2. TOTP Authenticator Apps: Time-based One-Time Passwords generated via mobile authenticator apps (e.g., Oracle Mobile Authenticator, Google Authenticator, Microsoft Authenticator).
  3. SMS / Voice Code: Time-based passcode delivered via cellular networks (recommended only as a fallback factor).
  4. Bypass Codes: Single-use emergency recovery codes generated by administrators for users with lost devices.
3. Identity Domain Sign-On Policy Architecture

A Sign-On Policy consists of an ordered sequence of rules evaluated sequentially whenever a user attempts to authenticate to the OCI Console or API.

Incoming Login Request
       │
       ▼
Rule 1: Is user in Administrators Group? ──► YES ──► Enforce FIDO2 / TOTP MFA
       │ NO
       ▼
Rule 2: Is connection from Corp VPN IP? ───► YES ──► Allow Username + Password
       │ NO
       ▼
Rule 3: Default Catch-All Rule ─────────────► Prompt for MFA + Prompt Password

[!IMPORTANT]
Rule Evaluation Priority Order
Sign-On Policy rules evaluate in top-to-bottom order. OCI applies the FIRST rule whose conditions match the incoming authentication request. High-priority rules (such as enforcing MFA for Tenant Administrators) must be placed at the top of the rule list.

4. OCI Web Console (GUI) Step-by-Step Walkthrough

Configuring Password Policies and Sign-On Rules is managed directly in the OCI Web Console GUI.

Step 1: Navigating to Sign-On Policies
  1. Log in to the Oracle Cloud Console (https://cloud.oracle.com).
  2. Open Navigation Menu (≡) ➔ Identity & Security ➔ Domains ➔ Select Target Domain (e.g., Default).
  3. Click Security ➔ Sign-On Policies in the domain left-hand menu.
Step 2: Enforcing MFA for Administrative Groups
  1. Click Default Sign-On Policy (or click Create Sign-On Policy for custom rules).
  2. Click Add Sign-On Rule.
  3. Configure the rule parameters:
  4. Rule Name: Enforce-MFA-For-Admins
  5. Conditions: Select User Group ➔ Choose Administrators and SecOps-Admins-Group.
  6. Actions:
    • Access: Select Allow.
    • Require Password: Enabled.
    • Require MFA: Enabled.
    • MFA Frequency: Select Every Access or Once per Session.
  7. Click Save Rule.
  8. Drag Enforce-MFA-For-Admins to position #1 in the rule priority list.

All administrators are now required to present an MFA factor upon logging into the OCI Console.

5. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Enabling MFA at the Tenancy Level Automatically Enrolls Users”
  • Reality: Creating an MFA Sign-On Rule prompts users to complete MFA enrollment upon their next login. Administrators should establish a grace period or communicate enrollment steps so users have their authenticator app or hardware key ready.
Misconception 2: “Administrators Locked Out by Lost MFA Devices Have No Recovery Option”
  • Reality: Another active tenancy administrator can generate a temporary Bypass Code in the user’s OCI Profile GUI, allowing the locked-out user to log in and register a replacement MFA device.
6. OCI Sign-On Rules vs. Google Cloud (GCP) Security Policies

For cloud architects familiar with Google Cloud, the following table compares authentication policy features:

Authentication FeatureGoogle Cloud (GCP)Oracle Cloud Infrastructure (OCI)Key Technical Difference
MFA EnforcementGCP 2-Step Verification (2SV) enforced per OUSign-On Policy Rules enforced per Identity DomainOCI allows fine-grained rule priorities based on group membership or IP range.
Hardware Key SupportSecurity Keys (FIDO2 / WebAuthn)FIDO2 / WebAuthn hardware authenticatorsBoth support phishing-resistant FIDO2 hardware keys natively.
Context-Aware SecurityGCP Context-Aware Access (Access Context Manager)Adaptive Risk-Based Sign-On Rules in Premium Identity DomainsBoth evaluate IP source, geographic risk, and session context during login.