1. Introduction to Authentication Hardening
Securing administrative access to Oracle Cloud Infrastructure (OCI) requires robust authentication controls. Credential compromise remains a primary attack vector targeting enterprise cloud environments.
OCI Identity Domains provide native Multifactor Authentication (MFA), customizable Password Policies, and Adaptive Risk-Based Sign-On Rules.
These tools allow security administrators to enforce strong authentication factors (such as FIDO2 hardware keys or TOTP authenticators) and dynamically evaluate session risk based on client IP, geographic location, and device context.
2. Supported Authentication Factors
OCI Identity Domains support multiple authentication factors:
- FIDO2 / WebAuthn Hardware Keys: The highest security factor (e.g., YubiKey, TouchID, Windows Hello). Resistant to phishing and man-in-the-middle attacks.
- TOTP Authenticator Apps: Time-based One-Time Passwords generated via mobile authenticator apps (e.g., Oracle Mobile Authenticator, Google Authenticator, Microsoft Authenticator).
- SMS / Voice Code: Time-based passcode delivered via cellular networks (recommended only as a fallback factor).
- Bypass Codes: Single-use emergency recovery codes generated by administrators for users with lost devices.
3. Identity Domain Sign-On Policy Architecture
A Sign-On Policy consists of an ordered sequence of rules evaluated sequentially whenever a user attempts to authenticate to the OCI Console or API.
Incoming Login Request
│
▼
Rule 1: Is user in Administrators Group? ──► YES ──► Enforce FIDO2 / TOTP MFA
│ NO
▼
Rule 2: Is connection from Corp VPN IP? ───► YES ──► Allow Username + Password
│ NO
▼
Rule 3: Default Catch-All Rule ─────────────► Prompt for MFA + Prompt Password
[!IMPORTANT]
Rule Evaluation Priority Order
Sign-On Policy rules evaluate in top-to-bottom order. OCI applies the FIRST rule whose conditions match the incoming authentication request. High-priority rules (such as enforcing MFA for Tenant Administrators) must be placed at the top of the rule list.
4. OCI Web Console (GUI) Step-by-Step Walkthrough
Configuring Password Policies and Sign-On Rules is managed directly in the OCI Web Console GUI.
Step 1: Navigating to Sign-On Policies
- Log in to the Oracle Cloud Console (
https://cloud.oracle.com). - Open Navigation Menu (
≡) ➔ Identity & Security ➔ Domains ➔ Select Target Domain (e.g.,Default). - Click Security ➔ Sign-On Policies in the domain left-hand menu.
Step 2: Enforcing MFA for Administrative Groups
- Click Default Sign-On Policy (or click Create Sign-On Policy for custom rules).
- Click Add Sign-On Rule.
- Configure the rule parameters:
- Rule Name:
Enforce-MFA-For-Admins - Conditions: Select User Group ➔ Choose
AdministratorsandSecOps-Admins-Group. - Actions:
- Access: Select Allow.
- Require Password: Enabled.
- Require MFA: Enabled.
- MFA Frequency: Select Every Access or Once per Session.
- Click Save Rule.
- Drag
Enforce-MFA-For-Adminsto position #1 in the rule priority list.
All administrators are now required to present an MFA factor upon logging into the OCI Console.
5. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Enabling MFA at the Tenancy Level Automatically Enrolls Users”
- Reality: Creating an MFA Sign-On Rule prompts users to complete MFA enrollment upon their next login. Administrators should establish a grace period or communicate enrollment steps so users have their authenticator app or hardware key ready.
Misconception 2: “Administrators Locked Out by Lost MFA Devices Have No Recovery Option”
- Reality: Another active tenancy administrator can generate a temporary Bypass Code in the user’s OCI Profile GUI, allowing the locked-out user to log in and register a replacement MFA device.
6. OCI Sign-On Rules vs. Google Cloud (GCP) Security Policies
For cloud architects familiar with Google Cloud, the following table compares authentication policy features:
| Authentication Feature | Google Cloud (GCP) | Oracle Cloud Infrastructure (OCI) | Key Technical Difference |
|---|---|---|---|
| MFA Enforcement | GCP 2-Step Verification (2SV) enforced per OU | Sign-On Policy Rules enforced per Identity Domain | OCI allows fine-grained rule priorities based on group membership or IP range. |
| Hardware Key Support | Security Keys (FIDO2 / WebAuthn) | FIDO2 / WebAuthn hardware authenticators | Both support phishing-resistant FIDO2 hardware keys natively. |
| Context-Aware Security | GCP Context-Aware Access (Access Context Manager) | Adaptive Risk-Based Sign-On Rules in Premium Identity Domains | Both evaluate IP source, geographic risk, and session context during login. |

