| name | snowflake-create-authentication-policy |
| description | Consult Snowflake CREATE AUTHENTICATION POLICY parameter reference before generating any CREATE AUTHENTICATION POLICY DDL. |
Before writing a CREATE AUTHENTICATION POLICY statement:
- Read
references/parameters.md to review all available parameters and their defaults.
- For each parameter, decide whether the user's request implies a non-default value.
- Include only the parameters that differ from the default or that the user explicitly requested.
- Never use
CREATE OR REPLACE — always use CREATE AUTHENTICATION POLICY IF NOT EXISTS.
- When the user specifies MFA requirements, select MFA_ENROLLMENT carefully: use
REQUIRED to force all users and REQUIRED_PASSWORD_ONLY only for password-based logins. Omit if leaving the default OPTIONAL behavior.
- For SECURITY_INTEGRATIONS, only list specific integration names when the user's SAML or OAuth setup is known; otherwise leave as the default
ALL.
- When configuring PAT_POLICY or WORKLOAD_IDENTITY_POLICY, always include each sub-property explicitly rather than relying on nested defaults.