---
name: azion-manage-conditional-access-by-ip-address
description: >-
  Create, update, and delete the policy that allows access to Azion only from the IP addresses you list, with the Azion API.
---

# Manage conditional access by IP address

**Preview**

You can manage the **Conditional Access by IP Address** policy through the Azion API. The policy holds a list of IP addresses, and only devices that connect from those addresses reach the platform. While the policy is active, Azion blocks access from any IP address that is not on the organization's allowlist. To block a user after failed sign-in attempts instead, refer to [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy/).

---

## Prerequisites

- *Account Owner* privileges, or the *managing policies* privilege. A request from a user with neither returns Error 403.
- An account with **Enterprise** or **Mission-Critical** Support. For the support tiers, refer to [Support guidelines](/en/documentation/support/).
- A personal token to replace `[Token]` in each request. To create one, refer to [Manage personal tokens](/en/documentation/guides/platform/account-and-billing/personal-tokens/).

The policy an organization sets applies to every account level under it.

---

## Create the policy

An account holds *1 configuration for this policy*, with up to 200 rules. A rule accepts IPv4 and IPv6 addresses. Searching or filtering policies by an IPv6 address is not supported.

The request body takes these keys:

| Key          | Type             | Description                                                                                                                                                                                                                             |
| ------------ | ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`       | String           | Name of the conditional access policy. Up to *255 characters*.                                                                                                                                                                          |
| `active`     | Boolean          | Whether the policy is active. Accepted values: `true` and `false`.                                                                                                                                                                      |
| `rules`      | Array of objects | The rules that set the behavior of the policy.                                                                                                                                                                                          |
| `name`       | String           | Inside the `rules` array, the name of one rule. Up to *255 characters*.                                                                                                                                                                 |
| `effect`     | String           | Effect of the rule. Accepted values: `allow` and `deny`.                                                                                                                                                                                |
| `resource`   | String           | The resource or resources the rule applies to, as an exact URN or a pattern match. Accepted value: `.*` (matches all resources). This endpoint also takes `platform` as a resource, which only defines global actions for the platform. |
| `actions`    | Array of strings | The action or actions the rule applies to. Accepted values: `create`, `retrieve`, `update`, and `destroy`. With `platform` as the resource, the only accepted action is `access`.                                                       |
| `condition`  | Text             | The conditions under which the rule applies.                                                                                                                                                                                            |
| `ip_address` | Array of strings | The IP addresses the condition evaluates. Required when the resource is `platform`.                                                                                                                                                     |

Send a `POST` request to the `auth/policies` endpoint:

```bash
curl --request POST \
  --url https://api.azion.com/v4/auth/policies \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "My Policy",
  "active": true,
  "rules": [
    {
      "name": "My policy rule",
      "effect": "allow",
      "resource": "platform",
      "actions": ["access"],
      "condition": {
        "ip_address": [
          "203.0.113.23",
          "198.51.100.0/24"
        ]
      }
    }
  ]
}'
```

The response is similar to this one:

```json
{
  "state": "executed",
  "data": {
    "id": 0,
    "name": "My Policy",
    "last_editor": "my_username",
    "last_modified": "2025-02-24T14:15:22Z",
    "active": true,
    "rules": [
      {
        "name": "My policy Rule",
        "effect": "allow",
        "resource": "platform",
        "actions": ["access"],
        "condition": {
          "ip_address": [
             "203.0.113.23",
          "198.51.100.0/24"
          ]
        }
      }
    ]
  }
}
```

The `state` key reports the result of the creation, and `id` identifies the policy. The policy is active. A user who tries to access the platform from an IP address outside the allowlist receives HTTP 403.

[Activity History](/en/documentation/guides/platform/account-and-billing/activity-history/) logs every access attempt of a valid user of the account, allowed or denied, for audit and monitoring.

The policy does not lock out the *Account Owner*. That exception comes with additional security measures, and it keeps a change of IP address or of the policy from locking the account.

---

## List the policies

The update and delete requests take the `id` of a policy, which this list returns.

Send a `GET` request to the `auth/policies` endpoint:

```bash
curl --request GET \
  --url https://api.azion.com/v4/auth/policies \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response is similar to this one:

```json
{
  "count": 123,
  "results": [
    {
      "id": 0,
      "name": "My policy",
      "last_editor": "my_username",
      "last_modified": "2025-02-24T14:15:22Z",
      "active": true,
      "rules": [
        {
          "name": "My policy rule",
          "effect": "allow",
          "resource": "platform",
          "actions": ["access"],
          "condition": {
            "ip_address": [
              "203.0.113.23",
              "198.51.100.0/24"
            ]
          }
        }
      ]
    }
  ]
}
```

Copy the `id` of the policy you want to change or remove.

---

## Update the policy status

A `PUT` request replaces every rule of the policy with the data in the body. The example sets `"active": false`, which turns the policy off. To change one or more fields and leave the others as they are, send a `PATCH` request instead.

Send a `PUT` request to the `auth/policies/<id>` endpoint, with the `id` from [List the policies](#list-the-policies) in place of `<id>`:

```bash
curl --request PUT \
  --url https://api.azion.com/v4/auth/policies/<id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "My policy",
  "active": false,
  "rules": [
    {
      "name": "My policy rule",
      "effect": "allow",
      "resource": "platform",
      "actions": ["access"],
      "condition": {
        "ip_address": [
              "203.0.113.23",
              "198.51.100.0/24"
            ]
      }
    }
  ]
}'
```

The response is similar to this one:

```json
{
  "state": "executed",
  "data": {
    "id": 0,
    "name": "My Policy",
    "last_editor": "my_username",
    "last_modified": "2025-02-24T14:15:22Z",
    "active": false,
    "rules": [
      {
        "name": "My policy Rule",
        "effect": "allow",
        "resource": "platform",
        "actions": ["access"],
        "condition": {
          "ip_address": [
            "203.0.113.23",
            "198.51.100.0/24"
          ]
        }
      }
    ]
  }
}
```

The response returns `"active": false`, and the policy no longer filters access by IP address.

---

## Delete the policy

Send a `DELETE` request to the `auth/policies/<id>` endpoint, with the `id` from [List the policies](#list-the-policies) in place of `<id>`:

```bash
curl --request DELETE \
  --url https://api.azion.com/v4/auth/policies/<id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json'
```

The response is similar to this one:

```json
{
  "state": "exectuted",
  "data": {
    "id": 0,
    "name": "My policy",
    "last_editor": "my_username",
    "last_modified": "2025-02-24T14:15:22Z",
    "active": true,
    "rules": [
      {
        "name": "My policy rule",
        "effect": "allow",
        "resource": "platform",
        "actions": ["access"],
        "condition": {
            "ip_address": [
              "203.0.113.23",
              "198.51.100.0/24"
            ]
        }
      }
    ]
  }
}
```

The account no longer has the policy.

For every endpoint the API exposes, refer to the [Azion API reference](https://api.azion.com/).

---

## Next steps

- [Activity History](/en/documentation/guides/platform/account-and-billing/activity-history.md): Review the access attempts the policy allowed and denied.
- [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy.md): Lock a user after repeated failed sign-in attempts.
- [Configure User Session Timeout](/en/documentation/guides/application-security/access-and-compliance/configure-user-session-timeout.md): End idle and long-running sessions on the account.
- [Troubleshoot Azion Console sign-in](/en/documentation/support/account-access.md): Regain access when a policy or a lost device blocks a user.
