auth0-forwarded-for
header is not supported.match
and not_match
operators in a single Tenant ACL rule to enforce fine-grained access policies.
Here is an example of a Tenant ACL rule that evaluates the geo_country_code
and geo_subdivision_code
signals to block all traffic from a given country except for a specific state, region, or province within that country.