IP Restriction for Apps

The "IP Restriction for Apps" feature identifies the IP address of the location from which access is attempted, allowing you to configure each SAML app to permit access only from specific IP addresses.

Note: This can only be configured for SAML apps. It is not supported for form-based authentication or Basic authentication using an ID and password.
Note: This feature is not applicable to step-up authentication.

Note: To use this feature, you need a TrustLogin Pro Plan or an optional contract. For pricing, click here

Setup

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and open "Settings" next to "IP Address Restriction."

    ipaddress_01.png

  2. Click "IP Restriction for Apps."

    ipaddress_02.png

  3. Click "Edit" to open the registration/edit screen and enter the following fields.

    IP Group Description: Enter notes about the IP addresses you are configuring.
    IP Address List: Enter the IP addresses to allow access from. If registering multiple addresses, separate them with line breaks.

    ipaddress_03.png
    ipaddress_04.png

  4. Click the "Save" button to register.

    ipaddress_05.png

  5. Next, add the apps that should be allowed access for the registered IP group.
    Click "Add App." 

    ipaddress_07.png

  6. Select the app you want to add and click the "Add" button to register it.
    Note: Office365 and G Suite, an app icon will be displayed for each domain. As a result of G Suite's specification, all G Suite domains share a single SAML configuration, so if you want to restrict the SAML app's IP address for G Suite, select the G Suite SAML app for all domains.

    ipaddress_08.png

    ipaddress_09.png

  7. Apps with IP address restriction configured will display a shield icon in the upper right corner on the user's My Page.

    ipaddress_10.png

  8. Authentication is only permitted for access from IP addresses registered in the IP Address List. Access from any IP address that is not registered will display the error screen shown below, and access will be blocked.

    ipaddress_11.png

IP Restriction for Apps

The "IP Restriction for Apps" feature identifies the IP address of the location from which access is attempted, allowing you to configure each SAML app to permit access only from specific IP addresses.

Note: This can only be configured for SAML apps. It is not supported for form-based authentication or Basic authentication using an ID and password.
Note: This feature is not applicable to step-up authentication.

Note: To use this feature, you need a TrustLogin Pro Plan or an optional contract. For pricing, click here

Setup

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and open "Settings" next to "IP Address Restriction."

    ipaddress_01.png

  2. Click "IP Restriction for Apps."

    ipaddress_02.png

  3. Click "Edit" to open the registration/edit screen and enter the following fields.

    IP Group Description: Enter notes about the IP addresses you are configuring.
    IP Address List: Enter the IP addresses to allow access from. If registering multiple addresses, separate them with line breaks.

    ipaddress_03.png
    ipaddress_04.png

  4. Click the "Save" button to register.

    ipaddress_05.png

  5. Next, add the apps that should be allowed access for the registered IP group.
    Click "Add App." 

    ipaddress_07.png

  6. Select the app you want to add and click the "Add" button to register it.
    Note: Office365 and G Suite, an app icon will be displayed for each domain. As a result of G Suite's specification, all G Suite domains share a single SAML configuration, so if you want to restrict the SAML app's IP address for G Suite, select the G Suite SAML app for all domains.

    ipaddress_08.png

    ipaddress_09.png

  7. Apps with IP address restriction configured will display a shield icon in the upper right corner on the user's My Page.

    ipaddress_10.png

  8. Authentication is only permitted for access from IP addresses registered in the IP Address List. Access from any IP address that is not registered will display the error screen shown below, and access will be blocked.

    ipaddress_11.png