What is IP Whitelisting?
IP Whitelisting helps restrict authentication to approved IP addresses and networks. Jellyfish includes IP Whitelisting as an additional access control layer applied during authentication.
This provides administrators with greater control over where users can access the platform from, enabling enforcement of network-level access policies alongside existing authentication mechanisms.
Administrators can configure individual IP addresses or IP ranges, allowing flexible policies that align with office networks, VPN endpoints, or other approved infrastructure.
Jellyfish can also automatically incorporate IP ranges published by Microsoft for services such as Azure and Entra, extending IP Whitelisting to Microsoft-hosted infrastructure while reducing the need for manual maintenance.
Benefits of Using IP Whitelisting
Reduce accidental logins from untrusted networks – helps prevent access from unintended or unauthorised locations.
Supports compliance and policy enforcement – helps teams enforce internal access policies for sensitive environments.
Quickly configurable – administrators can add or remove IP ranges in real time without affecting user credentials.
Additional peace of mind – Provides an added layer of control against unintended or misconfigured access.
Reduce ongoing administration – Automatically retrieve and update Microsoft IP ranges, removing the need for administrators to regularly monitor Microsoft publications and manually update their Jellyfish configuration.
Keep access controls current – Microsoft cloud infrastructure is continually changing. Automated updates help ensure configured Microsoft IP ranges remain aligned with the latest ranges published by Microsoft.
Integrate Microsoft cloud services into existing access controls – Seamlessly incorporate selected Azure and Entra IP ranges into Jellyfish's existing IP whitelisting functionality without requiring a separate access-control mechanism.
Maintain a responsive login experience – Microsoft IP lists are refreshed automatically. When a list requires updating during authentication, Jellyfish can use the most recently retrieved IP ranges while the latest list is fetched, avoiding unnecessary delays while maintaining the configured IP whitelist.
How Does IP Whitelisting Work?
When a user attempts to authenticate to Jellyfish, the platform evaluates the originating IP address of the request against the configured whitelist.
If the originating IP is not included in the whitelist, authentication is denied regardless of credential validity. If approved, authentication proceeds with standard credential validation.
Successful access therefore requires both:
- Valid user credentials, and
- An approved originating IP address.
The whitelist can contain both manually configured IP addresses and ranges, as well as IP ranges retrieved from configured Microsoft service tags.
How Does IP Whitelisting Work with Microsoft-published IP Ranges?
Administrators can configure selected Microsoft service tags to be automatically added to their trusted IP ranges. Jellyfish retrieves Microsoft's published IP range information and identifies the configured Microsoft services or service tags. The corresponding IP ranges are automatically incorporated into the tenancy-wide IP whitelist.
Microsoft's published service tag data is updated weekly. Jellyfish automatically refreshes configured Microsoft IP lists in the background, helping ensure access controls remain aligned with Microsoft's constantly evolving cloud infrastructure.
How Do I Configure IP Whitelisting in Jellyfish?
IP Whitelisting can be configured by an administrator through the Jellyfish web portal.
To enable and manage IP restrictions:
- Navigate to Configuration → Local Tenancy Configuration.
- Locate the Login Settings section.
- Locate the Restrict Login to IP Range / IP Whitelisting sub-section.
- Enter approved IPs or ranges, separated by commas or semicolons.
- Individual IP addresses are supported.
- IP ranges, including CIDR notation, are also supported.
- Submit the changes to apply the whitelist.
- Administrators should ensure their current IP address is included before enabling enforcement to avoid unintended access restrictions.
Once enabled, authentication attempts for the tenancy will be evaluated against the configured IP whitelist, including both manually configured IPs and the selected Microsoft IP ranges. Any external IP lists will continue to update automatically in the background.
How Do I Configure Microsoft-published IP Ranges?
Microsoft-published IP ranges can be configured by an administrator through the Jellyfish web portal.
To enable and manage external IP lists:
- Navigate to Configuration → Local Tenancy Configuration.
- Locate the Login Settings section.
- Locate the Restrict Login to IP Range / IP Whitelisting sub-section.
- Tick the Enable Microsoft IPs checkbox.
- Enter the name of a Microsoft service tag (e.g. AzureActiveDirectory or ActionGroup.AustraliaCentral), separated by commas or semicolons, and click the Fetch button.
- Review the fetched lists and submit the changes to apply the whitelist.
- Administrators should ensure their current IP address is included before enabling enforcement to avoid unintended access restrictions.
Considerations When Using IP Whitelisting
- IP whitelisting is not a foolproof security measure. IP addresses can be spoofed or masked in certain scenarios.
- Best used in combination with existing authentication measures (e.g., MFA, certificates, password policies).
- Works best for controlled or predictable network environments.
About Cogito Group
Cogito Group is an award-winning, Australian owned and operated ICT company, specialising in authentication, cloud security, identity management and data protection. Cogito Group protect the authentication methods used to access information using Identity and other security technologies. Cogito Group protect data not only from unauthorised access and disclosure, but also from being altered by an unauthorised third party or a trusted insider with malicious intent. This assists in the detection and prevention of fraud or other malicious activities by third parties or trusted insiders.