Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-1422

Allow customers to configure IP allow list by country (geoblocking)

    • 17
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Customers would like the ability to allowlist an entire geographic region of IP addresses e.g. select the entire country of Japan or Australia.

      One use case described was a hybrid work-from-home workforce that uses VPN for on-prem applications but their own network for other internet traffic.

            [ACCESS-1422] Allow customers to configure IP allow list by country (geoblocking)

            With an on premise Server instance of Confluence or Jira, obviously you can control who can connect to your instance. Not so with cloud instance. Access + Azure Conditional Access partially helps with this, since Microsoft Conditional access can prevent authentication except from specific country IP databases. However, connection attempts are still possible. If someone has credentials for a user, and they can connect, they can continue trying MFA requests until the user just presses OK. The missing piece of the puzzle here is the instance itself allowing connection ONLY from specific country IP databases. The existing IP allow listing interface is not flexible enough.

            Iain Whyte added a comment - With an on premise Server instance of Confluence or Jira, obviously you can control who can connect to your instance. Not so with cloud instance. Access + Azure Conditional Access partially helps with this, since Microsoft Conditional access can prevent authentication except from specific country IP databases. However, connection attempts are still possible. If someone has credentials for a user, and they can connect, they can continue trying MFA requests until the user just presses OK. The missing piece of the puzzle here is the instance itself allowing connection ONLY from specific country IP databases. The existing IP allow listing interface is not flexible enough.

              ecf27a037d15 Aditya Guntupalli
              464dd4441e51 Elelta D (Inactive)
              Votes:
              21 Vote for this issue
              Watchers:
              15 Start watching this issue

                Created:
                Updated: