Manage conditional access by IP address
Create, update, and delete the policy that allows access to Azion only from the IP addresses you list, with the Azion API.
You can manage the Conditional Access by IP Address policy through the Azion API. The policy holds a list of IP addresses, and only devices that connect from those addresses reach the platform. While the policy is active, Azion blocks access from any IP address that is not on the organization’s allowlist. To block a user after failed sign-in attempts instead, refer to Configure Account Lockout Policy.
Prerequisites
- Account Owner privileges, or the managing policies privilege. A request from a user with neither returns Error 403.
- An account with Enterprise or Mission-Critical Support. For the support tiers, refer to Support guidelines.
- A personal token to replace
[Token]in each request. To create one, refer to Manage personal tokens.
The policy an organization sets applies to every account level under it.
Create the policy
An account holds 1 configuration for this policy, with up to 200 rules. A rule accepts IPv4 and IPv6 addresses. Searching or filtering policies by an IPv6 address is not supported.
The request body takes these keys:
| Key | Type | Description |
|---|---|---|
name | String | Name of the conditional access policy. Up to 255 characters. |
active | Boolean | Whether the policy is active. Accepted values: true and false. |
rules | Array of objects | The rules that set the behavior of the policy. |
name | String | Inside the rules array, the name of one rule. Up to 255 characters. |
effect | String | Effect of the rule. Accepted values: allow and deny. |
resource | String | The resource or resources the rule applies to, as an exact URN or a pattern match. Accepted value: .* (matches all resources). This endpoint also takes platform as a resource, which only defines global actions for the platform. |
actions | Array of strings | The action or actions the rule applies to. Accepted values: create, retrieve, update, and destroy. With platform as the resource, the only accepted action is access. |
condition | Text | The conditions under which the rule applies. |
ip_address | Array of strings | The IP addresses the condition evaluates. Required when the resource is platform. |
Send a POST request to the auth/policies endpoint:
The response is similar to this one:
The state key reports the result of the creation, and id identifies the policy. The policy is active. A user who tries to access the platform from an IP address outside the allowlist receives HTTP 403.
Activity History logs every access attempt of a valid user of the account, allowed or denied, for audit and monitoring.
The policy does not lock out the Account Owner. That exception comes with additional security measures, and it keeps a change of IP address or of the policy from locking the account.
List the policies
The update and delete requests take the id of a policy, which this list returns.
Send a GET request to the auth/policies endpoint:
The response is similar to this one:
Copy the id of the policy you want to change or remove.
Update the policy status
A PUT request replaces every rule of the policy with the data in the body. The example sets "active": false, which turns the policy off. To change one or more fields and leave the others as they are, send a PATCH request instead.
Send a PUT request to the auth/policies/<id> endpoint, with the id from List the policies in place of <id>:
The response is similar to this one:
The response returns "active": false, and the policy no longer filters access by IP address.
Delete the policy
Send a DELETE request to the auth/policies/<id> endpoint, with the id from List the policies in place of <id>:
The response is similar to this one:
The account no longer has the policy.
For every endpoint the API exposes, refer to the Azion API reference.