Access policies
Access policies are the rules AuthCop follows every time a student signs in. They decide:
- whether the sign-in is blocked or challenged (the student must prove who they are)
- which sign-in methods the student can use
- which method the student sees first
Who can use this page: MFA Policy Manager or Global Administrator.

The policy list
Policies are listed in the order AuthCop checks them: highest Weight first.
The Default policy is always at the bottom. You can't open or change it. It blocks any sign-in that none of your other policies apply to.
If no policy applies to a student, their sign-in is blocked. Make sure every student is covered by at least one policy.
How AuthCop chooses the policies for a sign-in

Step 1: blocked countries. If the sign-in comes from a country on the Blocked Countries list, it is blocked. No policies are checked.
Step 2: find the policies that apply. AuthCop checks each enabled policy, from highest weight to lowest. A policy applies only when all of these are true:
- the student is in one of the policy's Included Groups. A policy with no included groups applies to all users.
- the sign-in is from one of the policy's Included Locations. A policy with no included locations applies to all locations.
- the sign-in is inside one of the policy's Time Ranges. A policy set to All Times (24/7) applies all the time.
- the sign-in is not from one of the policy's Excluded Locations.
If a policy applies and has Stop Processing Further Policies on Match turned on, AuthCop stops checking. Policies with a lower weight are ignored.
Leaving a tab empty means "no limit". For example, a policy with one included group, no locations and All Times (24/7) applies to that group, wherever and whenever they sign in. The empty Groups and Locations lists show a grey All users or All locations row to remind you.
Step 3: combine the policies that apply.
- If any of them has the action Block, the sign-in is blocked.
- Otherwise, the student is challenged. They can use every sign-in method that is turned on in any of the policies that apply.
- The method shown first is the Default method from the lowest-weight applying policy that has one.
- Methods that need setting up for each student (QR Code, TOTP, Passkey) only appear if the student has one.
- If the student ends up with no methods they can use, the sign-in is blocked.
Always blocked: sign-ins from the Tor network, and from places AuthCop can't identify, are blocked.
Example
| Policy | Weight | Action | Groups | Locations | Times | Methods |
|---|---|---|---|---|---|---|
| Block overseas | 200 | Block | All users | All locations, excluding "Australia" | All Times | — |
| Students | 100 | Challenge | "All Students" | All locations | All Times | QR Code (default), Teacher |
- A student in Australia: "Block overseas" doesn't apply (Australia is excluded). "Students" applies. They can use a QR code or ask a teacher.
- A student overseas: "Block overseas" applies, so they are blocked.
- A staff member who isn't in "All Students", signing in from Australia: neither policy applies, so the Default policy blocks them. Add a policy for them if they sign in through AuthCop too.
Create a policy
- Select Add Policy.
- Fill in each tab (explained below).
- Select Save.
Edit or delete a policy
- Open the policy and select Edit Policy.
- Make your changes and select Save. Or select Delete Policy and confirm.
To turn a policy off for a while without deleting it, turn off Enabled and save.
Details tab
| Setting | What it does |
|---|---|
| Name | A name to help you recognise the policy. |
| Weight | The order the policy is checked in. Higher numbers are checked first. |
| Enabled | When off, the policy is ignored at sign-in. |
| Stop Processing Further Policies on Match | When on, and this policy applies, lower-weight policies are not checked. |
| Policy Action | Challenge: the student must prove who they are. Block: the sign-in is stopped. |

Sign In Methods tab
Lists every method turned on in MFA Methods, grouped into Student, Caregiver and Teacher methods.
- Enabled: allow this method for sign-ins that this policy applies to.
- Default: make this the method the student sees first. They can still switch to another allowed method. You can only choose a default for an enabled method.
If a method is missing from the list, turn it on in MFA Methods first.
Locations tab
| Setting | What it does |
|---|---|
| Add exception for approved Travel Plans | Lets a student with an approved travel plan sign in from the countries in their plan, during their trip, even if that country is in an Excluded Location. Countries on the Blocked Countries list are still blocked. |
| Included Locations | The policy only applies to sign-ins from these locations. If you add none, the list shows All locations and the policy applies wherever the student is. |
| Excluded Locations | Sign-ins from these locations never match this policy. |
Groups tab
Included Groups: the policy only applies to students in at least one of these groups. Select Add Included Groups to add some. If you add none, the list shows All users and the policy applies to everyone.
Time Ranges tab
| Setting | What it does |
|---|---|
| All Times (24/7) | The policy applies at any time. |
| Timezone | The time zone your time ranges are in. Only shown when All Times is off. |
| Included Time Ranges | The days of the week and times the policy applies, for example Monday to Friday, 8:00 to 15:30. Select Add Time Range to add one, or the pencil to change one. When All Times is off, the policy only applies inside these ranges. |
When changes take effect
When you save a policy, AuthCop updates the sign-in page in the background. This usually takes a short time. Students who are already part-way through signing in keep the rules they started with.
Tips
- Start with one simple Challenge policy for all students, then add more specific policies with a higher weight.
- Give Block policies a high weight so they are checked first.
- After changing policies, test with a student account and check the Sign-in Logs.
- Every change to a policy is recorded in the Audit Logs.