---
title: "Policy Settings"
slug: "oas-pg-policy-settings-3-28"
updated: 2025-07-04T10:04:32Z
published: 2025-07-07T13:57:58Z
canonical: "docs.onespan.com/oas-pg-policy-settings-3-28"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onespan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Policy Settings

Policy settings can be configured via the Administration Web Interface:

- General policy settings, such as:
  - Whether local authentication requires an OTP generated by an authenticator or whether a password (or both) is required (see [Local authentication](/sec/docs/oas-pg-local-authentication-3-28))
  - Whether back-end authentication is to be used, and if so the back-end protocol, e.g. RADIUS or Microsoft Active Directory (see [Back-end authentication](/sec/docs/oas-pg-back-end-authentication-3-28))
- User policy settings, such as whether Dynamic User Registration is permitted, Password Autolearn, and Stored Password Proxy (see [Dynamic User Registration (DUR)](/sec/docs/oas-pg-dynamic-user-registration-dur-3-28)  and [Authentication without authenticators](/sec/docs/oas-pg-authentication-without-authenticators-3-28))
- Authenticator policy settings, such as whether auto-assignment or self-assignment is possible and the grace period (see [Authentication without authenticators](/sec/docs/oas-pg-authentication-without-authenticators-3-28))
- Application settings for one-step and two-step Challenge/Response authentication, for Virtual Mobile Authenticator, and backup Virtual Mobile Authenticator
- Policy settings for Digipass Authentication for Windows Logon, e.g. offline authentication settings (see [Digipass Authentication for Windows Logon](/sec/docs/oas-pg-digipass-authentication-for-windows-logon-3-28) )

Some policy properties can be overruled on the user level (see [User-specific authentication policy overrides](/sec/docs/oas-pg-user-specific-authentication-policy-overrides-3-28)). For more information about all configurable policy settings, refer to the OneSpan Authentication Server Administrator Reference.
