Security
The Security settings allow you to restrict access to your organization based on IP addresses. By configuring an IP allow list, only users connecting from approved IP addresses or ranges can use the application.
Opening Security Settings
Section titled “Opening Security Settings”- Navigate to Admin Settings → Security
- You will see the IP Allow List configuration panel
IP Allow List
Section titled “IP Allow List”The IP allow list lets you define which IP addresses or ranges are permitted to access your organization. When no restrictions are configured, all IP addresses are allowed.
How It Works
Section titled “How It Works”- Enter one or more CIDR ranges (IP address ranges in CIDR notation)
- Only users whose IP address falls within one of the specified ranges can access the application
- Users from other IP addresses will see a blocked access page
Configuring the Allow List
Section titled “Configuring the Allow List”- In the Allowed CIDR Ranges text field, enter your IP ranges
- Enter one CIDR range per line
- Click Save
Example CIDR ranges:
192.168.1.0/2410.0.0.0/82001:db8::/32Removing Restrictions
Section titled “Removing Restrictions”To allow access from all IP addresses again:
- Click Remove All Restrictions
- Confirm the action in the dialog
- All IP restrictions will be removed
Propagation Time
Section titled “Propagation Time”Changes to the IP allow list may take up to 60 seconds to take effect across all services.
Use Cases
Section titled “Use Cases”IP restrictions are useful for:
- Office-only access: Restrict access to your organization’s office network
- VPN enforcement: Ensure users connect through your corporate VPN
- Compliance requirements: Meet regulatory requirements for access control
Two-Factor Authentication (2FA)
Section titled “Two-Factor Authentication (2FA)”In the Two-factor authentication section, you can require all users in your organization to log in with an additional security step.
How It Works
Section titled “How It Works”When two-factor authentication is required, all users must protect their account with an authenticator app (e.g. Google Authenticator, Microsoft Authenticator, or Authy). During login, a one-time code from the app is requested in addition to the password.
Requiring 2FA for Your Organization
Section titled “Requiring 2FA for Your Organization”- Navigate to Admin Settings → Security
- Enable the Require two-factor authentication toggle
- The change applies at each user’s next login
Users who have not yet set up two-factor authentication will be prompted to do so at their next login before they can continue.
Disabling the 2FA Requirement
Section titled “Disabling the 2FA Requirement”Disable the toggle to lift the requirement. Users who have already set up 2FA keep their configuration — it simply is no longer enforced.
Next Steps
Section titled “Next Steps”- Manage Users — Control who has access to your organization
- Teams — Organize users into groups with specific permissions