Skip to content

Replace a policy branch rule

Request

Early AccessIdentity Engine
OAuth 2.0 scope:
  • okta.policies.manage

Replaces a rule in a policy branch.

Only applicable to ACCESS_POLICY type policies.

Path
policyIdstringrequired

id of the ACCESS_POLICY

Example:rst1d7xus97faIAgmti0
branchIdstringrequired

id of the policy branch

Example:rsb1d7xus97faIAgmti
ruleIdstringrequired

id of the policy rule

Example:ruld3hJ7jZh4fn0st0g3
Bodyapplication/jsonrequired
actionsobject(AccessPolicyRuleActions)

Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied.

conditionsobject(AccessPolicyRuleConditions)

Specifies conditions that must be met during policy evaluation to apply the rule. All policy conditions, as well as conditions for at least one rule must be met to apply the settings specified in the policy and the associated rule.

namestring

Name of the rule

priorityinteger or null

Priority of the rule

statusstring(LifecycleStatus)

Whether or not the rule is active. Use the activate query parameter to set the status of a rule.

Enum:"ACTIVE""INACTIVE"
systemboolean

Specifies whether Okta created the policy rule (system=true). You can't delete policy rules that have system set to true.

Default:false
typestring

Policy rule type. Branch rules are only supported for ACCESS_POLICY policies.

Value:"ACCESS_POLICY"
PUT
/api/v1/policies/{policyId}/branches/{branchId}/rules/{ruleId}
curl -i -X PUT \
  https://subdomain.okta.com/api/v1/policies/rst1d7xus97faIAgmti0/branches/rsb1d7xus97faIAgmti/rules/ruld3hJ7jZh4fn0st0g3 \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "ACCESS_POLICY",
    "name": "Require MFA for high and medium risk sign-ins",
    "conditions": {
      "riskScore": {
        "level": "MEDIUM"
      },
      "network": {
        "connection": "ANYWHERE"
      }
    },
    "actions": {
      "appSignOn": {
        "access": "ALLOW",
        "verificationMethod": {
          "type": "ASSURANCE",
          "reauthenticateIn": "PT0S",
          "constraints": [
            {
              "knowledge": {
                "types": [
                  "PASSWORD"
                ]
              },
              "reauthenticateIn": "PT0S"
            },
            {
              "possession": {
                "userPresence": "REQUIRED",
                "phishingResistant": "REQUIRED"
              }
            }
          ]
        }
      }
    }
  }'

Responses

Success

Bodyapplication/json
actionsobject(AccessPolicyRuleActions)

Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied.

branchInformationobjectread-only

Information about the branch this rule belongs to

conditionsobject(AccessPolicyRuleConditions)

Specifies conditions that must be met during policy evaluation to apply the rule. All policy conditions, as well as conditions for at least one rule must be met to apply the settings specified in the policy and the associated rule.

createdstring or null, (date-time)read-only

Timestamp when the policy branch rule was created

idstringread-only

Identifier for the rule

lastUpdatedstring or null, (date-time)read-only

Timestamp when the policy branch rule was last modified

namestring

Name of the rule

priorityinteger or null

Priority of the rule

statusstring(LifecycleStatus)

Whether or not the rule is active. Use the activate query parameter to set the status of a rule.

Enum:"ACTIVE""INACTIVE"
systemboolean

Specifies whether Okta created the policy rule (system=true). You can't delete policy rules that have system set to true.

Default:false
typestring

Policy rule type. Branch rules are only supported for ACCESS_POLICY policies.

Value:"ACCESS_POLICY"
Response
{ "id": "rul5o1bcd47keNFq2xm", "status": "ACTIVE", "name": "Require MFA for high and medium risk sign-ins", "priority": 1, "created": "2026-04-02T11:00:00.000Z", "lastUpdated": "2026-05-06T17:00:00.000Z", "system": false, "conditions": { "riskScore": {}, "network": {} }, "actions": { "appSignOn": {} }, "_links": { "self": {} }, "type": "ACCESS_POLICY" }