Configure security policies

Configure core security policies that govern access to ONESOURCE Compliance Hub, including SSO, MFA, and IP Authorization.
You can configure the following security policies:
  • Password policy:
    Length, complexity, expiration.
  • Account lockout policy:
    Failed attempts, lockout duration.
  • Single sign-on (SSO):
    Federation with your identity provider.
  • Multi-factor authentication (MFA):
    Enforce additional verification.
  • IP authorization:
    Restrict access to specific IP ranges.
  1. Configure SSO:
    1. In the ONESOURCE Administration area, open
      Authentication
      .
    2. Select your IdP type and upload metadata or certificates as required.
    3. Map attributes (name, email, groups) to ONESOURCE fields.
    4. Test with a pilot group before enabling for all users.
    tip
    Begin with staged rollouts (pilot, then broader deployment).
  2. Turn on MFA:
    1. In
      Authentication
      , turn MFA on for your tenant.
    2. Select the methods per policy (app, SMS, hardware token).
    3. Communicate setup steps to users and enforce on next sign-in.
  3. Configure IP authorization:
    1. Open
      IP Authorization
      .
    2. Add CIDR ranges that are permitted (for example, corporate VPN).
    3. Save and validate access from approved networks.
    tip
    • Align with corporate zero-trust standards.
    • Keep break-glass administrator accounts documented and secure.
Your security policies are configured and active for ONESOURCE Compliance Hub.
Troubleshooting
  • SSO failure:
    Check certificate validity and attribute mappings.
  • Locked out users:
    Review lockout thresholds. The administrator can reset.
  • IP blocks:
    Verify correct CIDR notation and current public IP.