IDP Support Center
  • Welcome
  • Getting started
    • What is IDP?
  • User Guide
    • User guide center
    • Get started with OXU
      • OXU Identity user guide
    • Account Management
      • Authentication
        • Sign up with Email and Password
        • Sign up with Google (optional)
        • Sign in with Email and Password
        • Google OIDC: Sign in to Google via OXU
        • Password requirements enforcement
        • Secure password hashing and storage
      • Account security
        • What should I do if I don't receive a verification code when signing up or forgot password?
        • Email verification
        • Two-Factor Authentication
          • Passkey authentication
          • 2FA-Email verification codes
          • MFA-Authenticator apps (TOTP)
          • MFA-Passkeys (FIDO2 / WebAuthn)
      • Data & Privacy
      • User Experience
        • Cross-platform web support
      • App Consent Management
    • Organization Admin App
      • Business Owner (Default Authority)
        • Organization Management
          • Organization creation
          • Domain ownership verification (DNS)
        • Organizational Structure
          • Organizational Units (OUs)
          • Workspaces
          • Hierarchical access scoping
        • Security & Governance
          • Enforced security policies
            • IP-Based access control
            • Geo-based access policies
            • Device and platform restrictions
          • Enforcing stronger authentication for risky login behavior
            • Risk Detection signals
            • Step-Up authentication
        • Roles & permissions
          • Assign role to user in Organization
          • Permissions list
      • SCIM – Automated user and workspace provisioning
        • What is SCIM used for?
        • User Lifecycle management
      • Administrator
        • Team & Access
          • Invite and manage users
          • Assign roles
          • Manage access at OU and Workspace level
            • Manage Access at Organizational Unit (OU)
            • Manage Workspace level
              • Team & Access – Members Management
        • Group management
        • Organization Unit
          • Create & manage Organization Units
          • Viewing and searching Organizational Units
          • Moving an Organizational Unit
          • Deleting an Organizational Unit
        • Manage activity logs of Organization's member
      • Become an OXU developer
      • App management - Workspace access
      • Report & Analytics Center
    • OXU Workspace
      • Guide to create workspace
      • Guide to manage workspace information
      • Guide to manage role and permissions
      • Applications
        • Guide to manage applications
        • OXU Developer
          • What is OXU developer
          • User guides
            • 1. Become OXU developer
            • 2. Create an app
            • 3. Input application info
              • About app ratings and reviews
            • 4. Config resource & security info
            • Security Best Practices
            • 5. Set up Pricing info
            • 6. Publish your app
              • Prepare before publishing your app
            • 7. Manage your app
              • App lifecycle
          • App versioning
        • OXU Store
          • What is OXU Store
          • 1. Register as an user
          • 2. Browsing & searching apps
          • 3. View app details
          • 4. Subscribe an app
            • Enable & Subscribe app for business workspace
          • 5. Manage subscriptions
          • 6. Rate & review an app
  • Support
    • Support center
      • What is Oten account & what can I do with Account Management App?
      • How to create account and password?
      • How to manage your Oten account information?
      • How to use MFA to protect your account?
      • What is WorkSpace & what can you do with WS?
      • What is Organization Admin app & what can you do with OAA?
    • Privacy Policy
    • Terms and conditions
      • Oten developer terms and conditions
      • Oten Store terms and conditions
    • FAQs
      • Store FAQs
      • Developer FAQ
    • Contact Us
  • Integration
    • Integration document
      • IDP integration
        • Environments: sandbox & production
        • Regular web application client
        • Native application client
        • Single page application client
        • SAML integration
        • Managing your integration applications
        • FAQ
      • What is SSO?
      • Why use SSO?
    • Provisioning connector
      • Google Workspace Configuration
    • Understand SSO flow
      • Overview
      • Flow Diagram
    • Developer Integration guide
      • Integration flow overview
    • Oten to OXU Migration guide
    • Prerequisites
      • Discovery Configuration
      • JAR Requirement - CRITICAL
      • JAR Complete Implementation Guide
      • PKCE Implementation Guide
        • Step 1: Choose OAuth Library
        • Step 2: Configure OAuth Client
        • Step 3: Implement Authorization Flow
        • Step 4: Handle Callback
        • Step 5: Token Management
      • Best practice
        • Security
      • Support & Troubleshoot
        • Common Errors
        • Debug and Troubleshooting
        • Contact Support
      • Appendix
        • Configuration Reference
        • Error Codes Reference
        • API Reference
        • Sample Code
        • Glossary
  • What's New
    • v1.0.29 - Aug 19, 2026
    • v1.0.28 - Aug 12, 2026
    • v1.0.27 - Aug 08, 2026
    • v1.0.26 - July 29 & 31, 2026
    • v1.0.25 - July 22, 2026
    • v1.0.24 - Jun 21, 2026
    • v1.0.23 - Jun 17, 2026
    • v1.0.22 - Jun 03, 2026
    • v1.0.21 - May 27, 2026
    • v1.0.20 - Apr 28, 2026
    • v1.0.19 - Apr 21, 2026
    • v1.0.18 - Apr 15, 2026
    • v1.0.17 - Apr 03, 2026
    • v1.0.16 - Mar 28, 2026
    • v1.0.15 - Mar 05 & 13, 2026
    • v1.0.14 - Feb 11, 2026
    • v1.0.13 - Jan 14, 2026
    • v1.0.12 - Jan 05, 2026
    • v1.0.11 - Jan 04, 2026
    • v1.0.10 - Dec 25, 2025
    • v1.0.9 - Dec 07, 2025
    • v1.0.8 - Nov 23, 2025
    • v1.0.7 - Nov 09, 2025
    • v1.0.6 - Oct 26, 2025
    • v1.0.5 - Sep 29, 2025
    • v1.0.4 - Sep 28, 2025
    • v1.0.3 - Sep 14, 2025
    • v1.0.2 - Aug 31, 2025
    • v1.0.1 - Aug 17, 2025
    • v1.0.0 - Aug 03, 2025
On this page
  1. User Guide
  2. Organization Admin App
  3. Business Owner (Default Authority)
  4. Security & Governance
  5. Enforced security policies

IP-Based access control

PreviousEnforced security policiesNextGeo-based access policies

Last updated 6 months ago

  • Overview
  • I am new. Where should I start?
  • Purpose
  • Prerequisites
  • Policy Modes
  • Supported IP Formats
  • I already understand. How do I proceed step by step?
  • Step-by-Step: Configure IP-Based Access Control
  • Result
  • Important Notes
  • Security Recommendations
  • Summary

Overview

IP-based access control allows organizations to allow or block user access based on specific IP addresses or IP ranges. This feature helps protect organizational resources by restricting access to trusted networks and preventing unauthorized connections.


I am new. Where should I start?

If you are new to IP-based access control, start by understanding the policy modes and preparing the IP addresses or ranges you want to manage.


Purpose

IP-based access control is designed to:

  • Restrict access to trusted IP addresses or networks

  • Block access from untrusted or suspicious IP ranges

  • Enhance security for internal systems and administrative access

  • Support compliance and security best practices


Prerequisites

Before configuring IP-based access control, ensure that:

  • You have administrator or security management permissions.

  • You know the public IP addresses or IP ranges to allow or block.

  • You understand the impact of access restrictions on users and integrations.

  • You have at least one trusted IP available to avoid accidental lockout.


Only users connecting from the specified IP addresses or IP ranges are allowed to access the organization. All other IP addresses are denied by default.

Use this mode when:

  • Access should be limited to trusted corporate networks

  • Protecting admin or internal-only systems


Users connecting from the specified IP addresses or IP ranges are denied access to the organization. All other IP addresses are allowed.

Use this mode when:

  • Blocking known malicious or untrusted IPs

  • Restricting access from specific locations or networks


You can specify IP addresses or ranges using the following formats:

  • Single IP address 192.168.1.1

  • Wildcard format 192.168.1.*

  • IP range 10.0.1.1 – 10.0.1.10

  • CIDR notation 192.168.1.0/24

Multiple IPs or ranges can be entered and separated by commas.


Follow the steps below to configure IP-based access control.



Under Basic info, provide the following:

  • Access security code A unique identifier used to reference this policy.

  • Access security name A descriptive name to help identify the policy.

  • Description (optional) Details about the purpose or scope of the policy.


Choose how access should be controlled:

  • Whitelist (Allow)

  • Blacklist (Deny)


  • Select Add condition and choose IP Allowlist.

  • Enter one or more IP addresses or IP ranges using the supported formats.

  • Review the entered IPs for accuracy.


  1. Review all settings and IP ranges.

  2. Confirm that at least one trusted IP is allowed if using Whitelist mode.

  3. Select Create access security to activate the policy.


Access to the organization is now allowed or blocked based on the configured IP policy.


  • IP-based access rules take effect immediately after activation.

  • In Whitelist mode, any IP not explicitly listed is denied.

  • In Blacklist mode, only listed IPs are denied.

  • Incorrect configuration may block legitimate users or integrations.


  • Use Whitelist mode for sensitive or admin-only access.

  • Keep IP policies documented and up to date.

  • Review IP rules regularly and remove unused entries.

  • Combine IP-based access control with MFA for stronger security.


  • IP-based access control restricts access using IP addresses or ranges.

  • Two policy modes are supported: Whitelist (Allow) and Blacklist (Deny).

  • Multiple IP formats are supported for flexibility.

  • Proper configuration helps prevent unauthorized access.

Policy Modes

Whitelist (Allow)

Blacklist (Deny)

Supported IP Formats

I already understand. How do I proceed step by step?

Step-by-Step: Configure IP-Based Access Control

Step 1: Open IP Access Control Settings

  • Profile Account → Admin

  • Welcome page Admin

  • Click on menu Security Policy → Access Security

  • Click button Create access security

Step 2: Enter Basic Information

Step 3: Select Policy Mode

Step 4: Add IP Ranges

Step 5: Review and Create Policy

Result

Important Notes

Security Recommendations

Summary

Sign in as an administrator :

Oten Admin | Security Policy & User management