Search
Search Compliance Hub Help and Support.

Configure security policies

Configure core security policies that govern access to ONESOURCE Compliance Hub, including SSO, MFA, and IP Authorization.
You can configure the following security policies:
  • Password policy:
    Length, complexity, expiration.
  • Account lockout policy:
    Failed attempts, lockout duration.
  • Single sign-on (SSO):
    Federation with your identity provider.
  • Multi-factor authentication (MFA):
    Enforce additional verification.
  • IP authorization:
    Restrict access to specific IP ranges.
  1. Configure SSO:
    1. In the ONESOURCE Administration area, open
      Authentication
      .
    2. Select your IdP type and upload metadata or certificates as required.
    3. Map attributes (name, email, groups) to ONESOURCE fields.
    4. Test with a pilot group before enabling for all users.
    tip
    Begin with staged rollouts (pilot, then broader deployment).
  2. Turn on MFA:
    1. In
      Authentication
      , turn MFA on for your tenant.
    2. Select the methods per policy (app, SMS, hardware token).
    3. Communicate setup steps to users and enforce on next sign-in.
  3. Configure IP authorization:
    1. Open
      IP Authorization
      .
    2. Add CIDR ranges that are permitted (for example, corporate VPN).
    3. Save and validate access from approved networks.
    tip
    • Align with corporate zero-trust standards.
    • Keep break-glass administrator accounts documented and secure.
Your security policies are configured and active for ONESOURCE Compliance Hub.
Troubleshooting
  • SSO failure:
    Check certificate validity and attribute mappings.
  • Locked out users:
    Review lockout thresholds. The administrator can reset.
  • IP blocks:
    Verify correct CIDR notation and current public IP.