Restrict Avvi access to your office network

An allowlist limits where Avvi can be used from, and it is checked at sign-in. Getting it wrong locks everybody out with no way back from inside the product.

An IP allowlist limits where Avvi can be used from. Anybody connecting from an address you have not listed is refused, whatever their password and whatever their role.

The check runs at sign-in, so a mistake here locks everybody out of the product rather than out of one part of it. There is no way back from inside Avvi.

Setting it up requires master or global administrator access, and the controls unlock in a particular order.

Before you begin

Know every address your team connects from. Home workers, a second office and a VPN exit are the three commonly forgotten.

Confirm those addresses are static. A restriction built on an address that changes stops working the next time it does.

You need master or global administrator access. Anybody else is refused when they save.

Turn it on

  1. Open Settings and go to the security section.
  2. Turn on Enable IP allowlist. The address box unlocks only once this is on.
  3. Enter every address that should be allowed.
  4. Select Save allowlist. A confirmation appears once the list has been stored.

If your own address is not among them, Avvi warns you before saving and names the address it can see.

Good to know

The address box and its save button stay disabled until the toggle is on, which is why the order above is not interchangeable.

Turning the toggle off applies straight away without a save, so backing out of a restriction is quicker than setting one up.

Adding the address Avvi reports in its warning is safer than adding the one you believe you have, because that is the address the check will actually see.

Verify it worked

Sign out and back in, and confirm you still get in.

Have a colleague on a different network confirm the same, before anybody relies on the restriction.

If something doesn’t look right

If a control is greyed out, your account is not allowed to change it. The setting is not broken and nothing is missing from the page.

If a setting is absent rather than greyed, the feature is switched off for your whole organisation rather than for you.

If the control works and saving fails, Avvi replies “Master admin access required”. That is the same permission problem, reported when you save rather than before.

If somebody is refused and should not be, their address is not on the list. Addresses change more often than people expect.

If everybody is refused at sign-in, nobody at your organisation can undo it. That has its own page and the route is Avvi support.

If saving is refused, you are not a master or global administrator and somebody who is will have to make the change.

To report a problem, open a support conversation from the Help drawer with the addresses you listed.

FAQ

Q: The setting is greyed out and I cannot change it.

A: Your account is not allowed to change that setting. Ask an administrator with full access to change it for you, or to add your group to the permission.

Q: Who do I ask to get access?

A: Any administrator with full access in Avvi. Tell them which setting you were trying to reach and what you needed to change.

Q: Does this cover the whole product?

A: Yes. The address is checked at sign-in, so a refused address cannot reach any of it.

Q: What happens to somebody outside the list?

A: They are refused and told their address is not authorised.

Q: Can I undo it?

A: Only from an allowed address. If nobody has one, Avvi support is the only route.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy