Identity Provider Geofencing
Identity Provider (IdP) Geofencing allows you to control access to the IDP by either blocking specific CIDRs or locations of the GPA Client or only allowing specific ones, with the option to add exceptions. This provides enhanced security control for the IdP by preventing access to the Login Portal from unwanted geolocations.
To configure geofencing for your IDP follow this procedure:
-
Log in to Enterprise Center.
-
In the Enterprise Center navigation menu, select Application Access > Identity & Users > Identity Providers.
-
Select the identity provider for which you want to add geofencing.
-
On the Settings page, go to the IDP Geofencing section.
-
Select one of the Access restriction mode:
Blocklist Mode. This mode blocks IdP access from GPA Clients in specific CIDRs or location, and everything else is allowed.
Allowlist Mode. This mode allows IdP access from GPA Clients in specific CIDRs or location, and everything else is blocked.
None. This mode allows IdP access from GPA Clients located anywhere. -
If you selected Blocklist Mode in 5, provide the CIDRs (either single IP addresses or CIDRs), Countries/areas you wish to Block access from the IdP. If you wish to exclude any CIDRs (either single IP addresses or CIDRs) or Countries/areas, provide them under Add Exception. These exceptions are allowed to access to the IdP.
If you selected Allowlist Mode in 5, provide the CIDRs (either single IP addresses or CIDRs), Countries/locations you wish to Allow access from the IdP. If you wish to exclude any CIDRs (either single IP addresses or CIDRs) or Countries/areas, provide them under Add Exception. These exceptions are blocked to access to the IdP.
NoteYou can also upload a CSV file containing the CIDRs separated by commas, spaces, or newline by clicking the upload icon and uploading from your machine.
- Select Save, to save changes. Select Save and Deploy, to save the changes and deploy the IdP.
Updated about 2 hours ago
