Managing Conditions

Prev Next

Creating a Condition

Note: You can create a Condition in the Policies Workspace (formerly Authorization Workspace), or in the WHEN step of the Policy Wizard when you create or edit a Policy. The Platform shows the same Condition types in both places.

To Create a Condition:

  1. Select the relevant Policies Workspace.
  2. Click the Assets & Conditions tab.
  3. In the Conditions section, click New Conditions. The Platform opens the New Condition screen.
  4. Enter a Name for the new Condition. Use a name that tells others what the Condition is for.
  5. Enter a Description for the Condition (optional).
  6. Choose whether the Condition applies to the Dynamic Authorization Service or to a specific Application.
  7. Select the Type of Condition. The types you can choose from depend on what you selected in the previous step. For details, see Available Condition Types.
  8. In the Define Condition Rules section, enter the required information (see below).
  9. Click Create. The Platform creates the Condition, opens the Condition Details screen, and adds the Condition to the Conditions area of the Policies Workspace.

Available Condition Types

Preproduction Feature

Note that this is a preproduction feature that is available only to preproduction Tenants

Your selection in step 6 determines which Condition types the Platform shows.

  • Dynamic Authorization Service: The Platform shows the predefined Condition types, which are Date & Time, IP, Identity Attribute, and Request Attribute.
  • Applications with Generic Condition Templates: The Platform shows the Condition types defined by the templates associated with that Application. Zscaler currently supports Generic Condition Templates. For more information, see Mapping Zscaler Conditions.
  • Applications without Generic Condition Templates: The Platform shows the predefined Condition types. This applies to Homegrown Applications and to Snowflake, Databricks, Microsoft Power BI, and Google BigQuery.

Note: The Policy Builder in the AI Workspace always shows the predefined Condition types.

About Date & Time Conditions

When defining a Date & Time Condition, you can specify the following options:

  • Months: Options include All, a single month, or any combination of specific months of the year.
  • Days: Options include All, a single day, or any combination of specific days of the week.
  • Time: Options include All Day (24 hours), or you can deselect All Day and specify a start and end time, along with the appropriate time zone.
  • Starting Date/Ending Date: You can specify a start and end date for when the Condition is active, or just a start date or end date.

You can use the OR option to specify another Time & Date range, creating a more complex rule.

About IP Conditions

When defining an IP Condition, you can specify the following options:

  1. Access Type: Options are Allow or Restrict.
  2. IP Range: Specify a valid CIDR IP range.

About Identity Attribute Conditions

When defining an Identity Attribute Condition, you can specify one or more rules:

  1. Select an Identity Attribute from the drop-down list. The Type field (Numeric or String) is populated automatically.
  2. Select the appropriate operator: Equals, Not Equals, Greater than, Less than, In, or Not In.
  3. Enter a value.
  4. To add another rule, click And or OR and define the elements of the rule again.

This Condition can also be used in SaaS Applications like Snowflake and Databricks.

About Request Attribute Conditions

When defining a Request Attribute Condition, you can specify one or more rules. A Request Attribute is an external parameter sent through the Request that factors into the Policy at run time:

  1. Select a Request Attribute from the drop-down list.
  2. Configure the Type field (Numeric or String) of the Attribute value.
  3. Select the appropriate operator: Equals, Not Equals, Greater than, or Less than.
  4. Enter a value.
  5. To add another rule, click And or OR and define the rule elements again.

© 2026 PlainID LTD. All rights reserved.