I turned on IP restrictions and locked us out

The check runs at sign-in, so nobody at your organisation can get in to undo it. Avvi support is the only route back.

Turning on an allowlist that does not include the address your team connects from refuses everybody, including whoever made the change.

Signing in still works. The check runs on the portal and on every request afterwards, which means the setting that would fix it sits behind the door it has closed, and no role gets past it.

Contact Avvi support by whatever means you normally would. That is the only route back, and it is not something to keep retrying.

Symptom

Access is refused and the refusal names your address rather than your account.

Everybody at your organisation gets the same result, including your master administrator.

Cause

The allowlist did not include the address your team actually connects from.

Avvi warns about this when saving, names the address it can see, and refuses to save until the warning is acknowledged. Getting here takes a deliberate click through that dialog.

The other cause is an address that was correct and has since changed. A connection given a new address periodically fails without anybody touching the setting.

Fix

  1. Stop retrying. The result will not change, and each attempt is recorded as a blocked sign-in.
  2. Contact Avvi support outside the product and say your organisation is locked out by the IP allowlist.
  3. Tell them the address your team connects from now, so it can be added rather than only having the restriction removed.
  4. Once access is back, confirm the address is static before turning the restriction on again.

Point three matters. Having the restriction lifted and then re-adding the same wrong address repeats the whole exercise.

If something doesn’t look right

If one person can still get in, you are not fully locked out. Have them fix the list before their own address changes.

If access returns by itself, your connection was given an address that happens to be on the list. Treat that as luck rather than a fix.

If you are unsure whether the allowlist is the cause, the refusal names an address rather than a permission, which distinguishes it from an ordinary access problem.

FAQ

Q: Can my master administrator fix it?

A: No. The address check has no exception for any role, so full access does not help.

Q: Will it expire on its own?

A: No. It stays until somebody changes it.

Q: How do I avoid this next time?

A: Add the address Avvi names in its warning, and have a colleague on another network confirm before relying on the restriction.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy