The identity policy has a default action, which is implemented for any connections that do not match any individual identity rules.
In fact, having no rules is a valid configuration for your policy. If you intend to use passive authentication on all traffic sources, then simply configure Passive Authentication as your default action.
- Open the Devices & Services page, select the device for which you are configuring an identity policy, and click Policy in the Management pane at the right.
- Click Identity in the Policy bar.
- Configure Identity Policy Settings if you have not done so already.
- At the bottom of the screen, click the Default Action button and choose one of the following:
Passive Auth-User identity will be determined using all configured passive identity sources for connections that do not match any identity rules. If you do not configure any passive identity sources, using Passive Auth as the default is the same as using No Auth.
No Auth—User identity will not be determined for connections that do not match any identity rules.
- When you are done configuring the Identity Policy Settings and policy default action, Deploy Configuration Changes from Defense Orchestrator to FTD.