Restrict access to the account
By default, access to the account is allowed from all IP addresses. The account owner and users with the iam.admin role can restrict account access — users will only be able to log into the account from IP addresses and subnets that the account owner or iam.admin have added to the allowed list.
The access restriction applies to logging in through the control panel.
Add an address to the authorized list
Before adding an IP address, ensure that it is static. You can check the address type with your provider.
-
In the control panel, on the top menu, click IAM.
-
Go to the ACL section.
-
Click Add Addresses.
-
To retain access to your account, first add your current IP address.
-
Click Add another address.
-
Enter an address. You can add:
- IPv4 address;
- IPv6 address;
- subnet in the format
198.51.100.0/29.
-
Optional: enter a comment. For example, specify who the provided IP address or subnet belongs to. The maximum length of a comment is 256 characters.
-
Click Add. Sessions from addresses not included in the list will be terminated, and access to the account from them will be denied.
Remove an address from the authorized list
The account owner and iam.admin can delete one or all addresses from which access to the account is allowed. When all addresses are deleted, all restrictions will be removed — users will be able to access the account from any address.
Remove one address
Remove all addresses
- In the control panel, on the top menu, click IAM.
- Go to the ACL section.
- In the menu for the address, select Delete.
- To confirm the deletion, enter the address.
- Click Delete.