Symptom
- Restricting Access by IP Address
- If you would like to add an additional layer of security for access to the SuccessFactors application, you can request access to be restricted to only certain IP addresses.
- Self-Service tool - IP Restriction Management
- Can we restrict access by IP address for some users and not others (i.e restrict SSO users and not PWD users)?
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Environment
SAP SuccessFactors HXM Suite
Resolution
- The SuccessFactors Application supports IP address restriction as a security method.
- With this method the client provides specific IP addresses (single ones or ranges of addresses) that will be able to access the SuccessFactors Application.
- Only users from these addresses can access the SuccessFactors Application and all others will get a notification when trying to login that they do not have access.
Here is a quick video describing the new feature:
Media not computed.
NOTE 1:
As of b1708 release, you can now use self-service to manage IP restrictions from Admin center.
First, you need to assign the following permission to the user who will be allowed to manage the restrictions: permission called "IP Restriction Management" in the "Manage system properties" section.
We recommend that the user log out and into the system again after you have assigned this permission.
NOTE 2:
Starting b2011 release, we have added a tool tip on the IP restriction management permission to provide administrators a high level information on what the permission is for.
- Next, the admin user will be able to access the tool called "IP Restriction Management" in Admin Center.
- To add a restriction, press the "+" symbol on the top right .
This will let you add two types of restrictions:
- Single IP Address:
Enter the desired IP address and press save. - IP Address range:
Enter the start and end IP for this range and press save. - Please be sure to provide all IP addresses for your company (offices, remote workers, etc).
If there are employees that are trying to access the application in an IP address other than the ones provided, they will not be able to log in. - Also make sure that you add your own IP to this list. If not, and you made a mistake, you could potentially end up locking out all users including yourself from the system.
To check your public IP you can simply search for "what is my IP" in any search engine (for example this search in Google) - You can turn off IP restrictions for external users. To do so, press on the "cog" button on the top right.
This will display 3 options that can be enabled separately. Press save after you have finished selecting the options. - You can delete any previous stored value by pressing the delete button for that particular IP or range.
You can also edit the previously configure value by pressing the pencil button on the respective configured IP or Range.
NOTE:
- Once IP restrictions have been configured, these restrictions are applied to all users. It is not possible to restrict access for some users and not others (i.e SSO/PWD users).
- Please enter IPv4 addresses only. IPv6 is not supported.
See Also
Keywords
access list, filter, SuccessFactors, SAP, IP, Restrict, ipv6 , KBA , whitelist , whitelisting , LOD-SF-PLT-IPR , SF Server IP related Queries & IP Restriction , LOD-SF-PLT , Platform Foundational Capabilities , How To