Restrict access to the account
By default, access to the account is allowed from all IP addresses. The account owner and users with the iam.admin role can restrict account access — users will only be able to log into the account from IP addresses and subnets that the account owner or iam.admin have added to the allowed list.
The access restriction applies to logging in through the control panel.
Add an address to the authorized list
Before adding an IP address, make sure the IP address is static. You can check the address type with your provider.
-
In the control panel, on the top menu, click IAM.
-
Go to the ACL section.
-
Click Add Addresses.
-
To retain access to your account, first add your current IP address.
-
Click Add another address.
-
Enter an address. You can add:
- IPv4 address;
- IPv6 address;
- subnet in the format
198.51.100.0/29.
-
Optional: enter a comment. For example, specify who the provided IP address or subnet belongs to. The maximum length of a comment is 256 characters.
-
Click Add. Sessions from addresses not included in the list will be terminated, and access to the account from them will be denied.
Remove an address from the authorized list
The account owner and iam.admin can remove one address or all addresses from which access to the account is permitted. When removing all addresses, all restrictions will be lifted — users will have access to the account from any address.
Remove one address
Remove all addresses
- In the control panel, on the top menu, click IAM.
- Go to the ACL section.
- In the address menu, select Delete.
- To confirm the deletion, enter the address.
- Click Delete.