Skip to content

Set workspace login security

Control who can sign in to a workspace's Backoffice by limiting the source addresses that are accepted and by choosing whether two-factor authentication is optional or required.

Login security is set per workspace and applies to everyone who signs in to that workspace. It has two parts: a login IP allowlist and a two-factor authentication policy.

Prerequisites

  • You are signed in with a role that lets you manage security for your active workspace.

Open workspace security

In the left sidebar, open Workspace security for your active workspace. The page shows the login IP allowlist and the two-factor policy for that workspace.

Restrict sign-in by IP address

The Login IP allowlist limits which source addresses may sign in to this workspace. When the list is empty, any address is allowed.

To add an allowed address or range:

  1. In the allowlist field, enter a single IP address (for example 203.0.113.7) or a CIDR range (for example 203.0.113.0/24).
  2. Click Add IP / range. The entry appears as a row in the list.

To remove an entry, click Remove on its row. Removing the last entry returns the workspace to allowing any address.

Warning

Adding your own current address before you rely on the allowlist avoids locking yourself out. Once the list has any entry, sign-ins from addresses outside it are refused for this workspace.

Set the two-factor policy

The two-factor policy decides whether users in this workspace must protect their sign-in with a second factor from an authenticator app.

  • Leave Require two-factor authentication off to make it optional — each user chooses whether to enable it.
  • Turn it on to make it mandatory — users in this workspace must complete two-factor setup before they can reach the rest of the Backoffice.

Click Save to apply your changes.

Note

This page sets the policy only. Users enroll in two-factor authentication during the sign-in flow, where they scan a code into their authenticator app and save one-time recovery codes. If a user is locked out, an administrator resets their enrollment from the operator users page.