Skip to content

Security

The Security settings allow you to restrict access to your organization based on IP addresses. By configuring an IP allow list, only users connecting from approved IP addresses or ranges can use the application.

  1. Navigate to Admin Settings → Security
  2. You will see the IP Allow List configuration panel

The IP allow list lets you define which IP addresses or ranges are permitted to access your organization. When no restrictions are configured, all IP addresses are allowed.

  • Enter one or more CIDR ranges (IP address ranges in CIDR notation)
  • Only users whose IP address falls within one of the specified ranges can access the application
  • Users from other IP addresses will see a blocked access page
  1. In the Allowed CIDR Ranges text field, enter your IP ranges
  2. Enter one CIDR range per line
  3. Click Save

Example CIDR ranges:

192.168.1.0/24
10.0.0.0/8
2001:db8::/32

To allow access from all IP addresses again:

  1. Click Remove All Restrictions
  2. Confirm the action in the dialog
  3. All IP restrictions will be removed

Changes to the IP allow list may take up to 60 seconds to take effect across all services.

IP restrictions are useful for:

  • Office-only access: Restrict access to your organization’s office network
  • VPN enforcement: Ensure users connect through your corporate VPN
  • Compliance requirements: Meet regulatory requirements for access control

Account Lockout After Failed Login Attempts

Section titled “Account Lockout After Failed Login Attempts”

Ayunis Core automatically locks a user account when too many consecutive login attempts fail with the wrong password. This safeguard prevents unauthorized access through systematic password guessing.

  • The user sees the message “Your account is locked” during sign-in and can no longer log in.
  • In the user list under Admin Settings → Users, the status Locked is displayed.
  • An administrator can manually unlock the account at any time (see Manage Users).

In the Two-factor authentication section, you can require all users in your organization to log in with an additional security step.

When two-factor authentication is required, Ayunis Core ensures an additional security step during sign-in. Users with an Ayunis password use an authenticator app (e.g. Google Authenticator, Microsoft Authenticator, or Authy). For organization sign-in, a second factor already verified there meets the requirement. Otherwise, an authenticator app must also be set up.

  1. Navigate to Admin Settings → Security
  2. Enable the Require two-factor authentication toggle
  3. The change applies at each user’s next login

Users who have not yet set up two-factor authentication and whose organization sign-in does not confirm an already verified second factor will be prompted to set it up at their next login before they can continue.

Disable the toggle to lift the requirement. Users who have already set up 2FA keep their configuration — it simply is no longer enforced.

  • Manage Users — Control who has access to your organization
  • Teams — Organize users into groups with specific permissions