IP Access Filtering

IP Access Filtering allows administrators to restrict access to their Haiilo tenant based on approved IP addresses or IP ranges. By limiting access to trusted corporate networks, VPNs, or other approved locations, organisations can add an additional layer of protection beyond user authentication.

Requests originating from IP addresses outside the configured allow list are blocked before they can access tenant-specific resources, helping organisations enforce network-based access policies and strengthen access security.

This feature is available as part of the Advanced Security Add-on. Please contact your personal Account Manager for further information.

What is IP Access Filtering?

IP Access Filtering allows administrators to define a list of approved IP addresses or network ranges that are permitted to access their Haiilo environment.

Once configured, all incoming requests are evaluated against the allow list. If a request originates from an IP address that is not included in the configured rules, access is denied.

Supported entries include:

  • Individual IP addresses such as 1.2.3.4
  • CIDR subnet ranges such as 127.0.0.0/24

What are the benefits of IP Access Filtering?

  • Restrict access to approved corporate networks
  • Reduce exposure to unauthorised access attempts
  • Support internal security and compliance requirements
  • Provide an additional layer of protection beyond user authentication
  • Enforce network-based access policies without requiring dedicated infrastructure

Important integration considerations

If your organisation uses SCIM provisioning, OAuth-based integrations, or external plugins, you may need to configure endpoint exclusions to ensure these integrations continue to function when IP Access Filtering is enabled.

Certain integrations rely on requests originating from cloud-hosted services whose source IP addresses cannot always be reliably predicted or controlled.

To accommodate these scenarios, specific endpoints can optionally be excluded from IP filtering.

Supported exclusions include:

  • SCIM API endpoints
  • OAuth authentication endpoints
  • Plugin API endpoints

Endpoint exclusions are optional and are not enabled automatically. All supported endpoints remain protected by IP filtering unless an administrator explicitly enables an exclusion.

How do I configure IP Access Filtering?

To configure IP Access Filtering:

  1. Open the Haiilo administration.
  2. Go to Security & Privacy and select IP Filter.
  3. Add one or more approved IP addresses or CIDR ranges.
  4. Review the validation information displayed.
  5. Save the configuration.

After saving, the configured rules are applied immediately to incoming requests.

Built-in safety mechanisms

To help prevent accidental lockouts, Haiilo validates the administrator's current IP address before allowing configuration changes to be saved.

If the current administrator session is not connected from an approved IP address:

  • A warning is displayed.
  • The Save button is disabled.
  • The configuration cannot be saved until the current IP address is included in the allow list.

This safeguard helps ensure that administrators do not accidentally remove their own access while configuring the feature.

End-user experience

When users access the tenant from an approved network, no additional action is required.

If a user attempts to access the tenant from an IP address that is not part of the configured allow list, access is blocked and a clear, localised error message is displayed explaining why access is unavailable.

Security best practices

To achieve the best results with IP Access Filtering, Haiilo recommends:

  • Only allowing trusted corporate networks and VPN endpoints
  • Regularly reviewing configured IP ranges
  • Removing obsolete entries when infrastructure changes
  • Testing configurations before enabling restrictions in production
  • Maintaining documented ownership of the allow list
  • Combining IP restrictions with additional security measures such as Multi-Factor Authentication for layered protection

Frequently asked questions

  • Yes. IP Access Filtering supports both individual IP addresses and CIDR subnet ranges.
  • Access to the tenant is blocked and the user receives a message explaining that access is not permitted from their current IP address.
  • No. The configuration interface validates the current administrator IP address before changes can be saved. If the current IP address is not included in the allow list, the Save button is disabled until the issue is resolved.
  • Certain integrations rely on requests originating from cloud-hosted services whose source IP addresses may be difficult or impossible to predict. Endpoint exclusions allow these integrations to continue functioning while maintaining IP restrictions for normal user access.
  • Not necessarily. SCIM endpoints can be excluded from filtering, allowing identity providers such as Microsoft Entra ID to continue provisioning users when IP restrictions are enabled.
  • OAuth authentication endpoints can be excluded from filtering. This is particularly important for integrations that rely on machine-to-machine authentication, including some SCIM provisioning workflows.
  • Plugin API endpoints can be excluded from IP filtering. This allows plugins hosted on external infrastructure to continue accessing the Haiilo APIs required for their functionality.
  • Endpoint exclusions only remove the IP address restriction for the selected endpoint group. Authentication, authorisation, permissions, API credentials, and all other security controls remain in place.
  • Private cloud customers already have access to IP-based restrictions through infrastructure-level firewall configurations. The current IP Access Filtering feature is primarily intended for multi-tenant cloud environments.
  • Organisations should review and update their IP filter configuration whenever corporate internet connections, VPN providers, office locations, or network infrastructure change.
  • Haiilo Support can assist with configuration recovery if network conditions or IP assignments change unexpectedly. Haiilo office and VPN IP addresses are automatically included in the allow list to help maintain supportability and recovery options.
  • Availability depends on your subscription and commercial agreement. Customers interested in using IP Access Filtering should contact their Haiilo representative for availability information.

Was this article helpful?

0 out of 0 found this helpful