Skip to content

Network Zones

The Network Zones API provides operations to manage system default and custom zones in your Okta org. Network Zones are configurable boundaries that you can use to grant or restrict access to resources in your organization. They're used for two purposes:

  • POLICY: Network Zones used to guide policy decisions
  • BLOCKLIST: Network Zones used to deny access from certain IP addresses, locations, Autonomous System Numbers (ASNs), proxy types, or IP service categories before policy evaluation

Note: The Network Zone blocklist applies to all URLs for the org.

See Network zones in the Okta product documentation.

Your Okta org provides the following default system Network Zones that you can modify and use:

  • LegacyIpZone: The system default IP Network Zone
  • BlockedIpZone: The system default IP Blocklist Network Zone
  • DefaultEnhancedDynamicZone: The system default Enhanced Dynamic Network Zone

You can create and use the following custom Network Zones:

  • IP Network Zone (IP): Allows you to define network perimeters around a set of IPs
  • Dynamic Network Zone (DYNAMIC): Allows you to define network perimeters around location, IP type, or ASNs
  • Enhanced Dynamic Network Zone (DYNAMIC_V2): Extends the Dynamic Network Zone and allows you to include or exclude specific locations, ASNs, or IP service categories

Note: To create multiple Network Zones, you must have Adaptive MFA enabled in your Okta org.

Languages
Servers
https://{yourOktaDomain}