Two part question.
-
Is there a way to control geo-location access? For example all users in the US are authenticated and all attempts outside the US are restricted.
-
When a user travels outside the US create a policy that allows them to authenticate while all other users not traveling are still restricted.