Configure security policies
Configure core security policies that govern access to ONESOURCE Compliance Hub, including SSO, MFA, and IP Authorization.
You can configure the following security policies:
- Password policy:Length, complexity, expiration.
- Account lockout policy:Failed attempts, lockout duration.
- Single sign-on (SSO):Federation with your identity provider.
- Multi-factor authentication (MFA):Enforce additional verification.
- IP authorization:Restrict access to specific IP ranges.
- Configure SSO:
- In the ONESOURCE Administration area, openAuthentication.
- Select your IdP type and upload metadata or certificates as required.
- Map attributes (name, email, groups) to ONESOURCE fields.
- Test with a pilot group before enabling for all users.
tipBegin with staged rollouts (pilot, then broader deployment). - Turn on MFA:
- InAuthentication, turn MFA on for your tenant.
- Select the methods per policy (app, SMS, hardware token).
- Communicate setup steps to users and enforce on next sign-in.
- Configure IP authorization:
- OpenIP Authorization.
- Add CIDR ranges that are permitted (for example, corporate VPN).
- Save and validate access from approved networks.
tip- Align with corporate zero-trust standards.
- Keep break-glass administrator accounts documented and secure.
Your security policies are configured and active for ONESOURCE Compliance Hub.
Troubleshooting
- SSO failure:Check certificate validity and attribute mappings.
- Locked out users:Review lockout thresholds. The administrator can reset.
- IP blocks:Verify correct CIDR notation and current public IP.