Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7227: How to block user access to an application from an specific IP address or several IP addresses?

Centrify Identity Service, App Edition ,  

20 July,16 at 04:10 AM

Applies to: All versions of Centrify Identity Service

Question:

User may not be allowed to access an application from a specific IP address. Is there a way to block user from a specific IP when accessing an application?

Answer:

This can be done by editing application policy script (Cloud Manager > Apps > Click on the target app > Policy > Script):

if(context.ipAddress == 'XX.XXX.XX.123'){             
trace("allowed ip");       
policy.Locked = false;
}  
else{     
trace("non-allowed ip");              
policy.Locked = true;     
}             

}             

If a number of IP addresses need to be blocked, the following script can be used instead:


var ipArray = ['XX.XXX.XX.24', 'XX.XXX.XX.335', 'XX.XXX.XX.183'];
if(ipArray.indexOf(context.ipAddress) >= 0){
trace("allowed ip");
policy.Locked = false;
}
else{
trace("non-allowed ip");
policy.Locked = true;
}
}


Note: IP range cannot be defined in the script.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.

Related Articles

No related Articles