Administrator Sign-In Policies

The Administrator Sign-In Policies screen allows you to enforce context-aware authentication rules for Timus Manager administrators using behavior-based Zero Trust principles. These policies help you protect your infrastructure, applications, and sensitive data by dynamically responding to sign-in attempts based on risk factors and behavioral context.

📍 To access this screen, go to Zero Trust Security → Administrator Sign-In Policies

The main table lists both default and custom sign-in policies:

ColumnDescription
NameName of the policy
DescriptionSummary of its purpose
StatusCurrent status of the policy

Policies higher in the list are evaluated first. You can reorder them using drag & drop to change priority.


Create a Administrator Sign-In Policy

Click Create New to open the policy builder. You’ll configure the policy using four tabs:

Source

Specify the administrators this rule applies to:

  • Add a Name and Description (optional)
  • Select one or more administrators from the system

Condition

Define the sign-in context in which the policy is enforced:

FieldDescription
Risk LevelAny, Low, Medium, or High
Behavior ConditionsSelect one or more behavior conditions (see supported types below)
Behavior Match LogicAll Selected Behaviors (AND) or Any Selected Behavior (OR)
ScheduleLimit policy to specific times/days if needed

Supported Behavior Types

Behavior TypePurpose
New DeviceDetects sign-ins from previously unseen devices
Out of RadiusFlags sign-ins from locations outside usual geographic range
New CountryDetects logins from new countries based on past activity
Impossible TravelDetects geographically implausible login movement
Last Sign-In DateTriggers if administrator hasn’t signed in recently
Untrusted IPFlags risky IPs (proxy, botnet, TOR, abuse score, etc.)
Breached EmailFlags email addresses found in breach databases
Consecutive Failures at Same AccountDetects brute-force attempts on a single user
Consecutive Failures at Any AccountDetects credential stuffing attempts across administrators

Action

Specify how the system should respond if the policy conditions are met:

OptionBehavior
AllowPermit access
DenyDeny access
MFA - EmailRequire email-based OTP
MFA - Authenticator AppRequire app-based TOTP
Deny and Block IPDeny access and blacklist the IP address

You can configure multi-step MFA (e.g., Email + App fallback) to strengthen layered authentication.

Alerts & Notifications

Improve incident visibility and team coordination with real-time alerts:

  • Alerts:
    • Define Title, Severity, and Status
    • Choose Trigger Results: Success, Failure, Timeout
  • Notifications:
    • Define Title, Severity, and Status
    • Choose Trigger Results: Success, Failure, Timeout
    • Choose whether to notify matching administrators, specific administrators, or external recipients

Updated

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.