OptionalapprovalAdministrators who can approve a temporary authentication request.
OptionalapprovalRequires the user to request access from an administrator at the start of each session.
OptionalconnectionThe rules that define how users may connect to targets secured by your application.
The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action. Available values: "allow", "deny", "nonIdentity", "bypass".
OptionalexcludesRules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
OptionalincludesRules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.
OptionalisolationRequire this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature.
OptionalmfaConfigures multi-factor authentication (MFA) settings.
The name of the Access policy.
OptionalpurposeA custom message that will appear on the purpose justification screen.
OptionalpurposeRequire users to enter a justification when they log in to the application.
OptionalrequiresRules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
OptionalsessionThe amount of time that tokens issued for the application will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m, h.
Identifier.