Description: Defines how and when MFA is required (e.g., always, only on wp-admin, remembered/trusted devices).
How it works: Policies evaluate context (role, device trust, session age) to decide whether to prompt for MFA.
How to access / configure:
- WP Admin → AegisShield → Login Guard → MFA (Pro).
- Choose enforcement mode and trusted device settings.
- Save changes and test login flows.
Recommended setting: Enable trusted devices with a 30‑day lifetime to reduce friction while maintaining security.
