Configure access rules
Set authentication requirements and session duration for a zone
Configure access rules
Each zone can require additional authentication before granting access and limit how long a session stays active. These settings are enforced by the Threatmatic control plane at connection time.
Prerequisites
- An existing zone with at least one device selector configured
Steps
Open the zone
- Go to Console → Zones
- Click the zone you want to configure
Require authentication
Toggle Require Authentication to enforce identity verification before a device can connect to the zone.
When enabled, the connecting user must complete an authentication step (SSO, MFA, or API key — depending on your identity configuration) each time a new session starts.
Enable this for zones that serve sensitive resources such as finance systems, production infrastructure, or privileged admin tooling.
Set session duration
Enter a Session Duration (in minutes). When the session expires, the device must re-authenticate to regain access.
| Use case | Recommended duration |
|---|---|
| High-trust internal tools | 480 min (8 hours) |
| Sensitive / privileged access | 60 min |
| Short-lived contractor access | 30 min |
Leave blank to allow indefinite sessions (not recommended for sensitive zones).
Save
Click Save. The updated policy takes effect on the next device sync — active sessions are not interrupted until they expire.
Next steps
How is this guide?
Last updated on