Illizeo can limit the IP addresses people sign in from. That is the only criterion available: there is no country-level filtering.
Restriction levels #
| Mechanism | Effect | Scope |
|---|---|---|
| IP allowlist | If it holds at least one entry, only those addresses can sign in | The whole customer workspace |
| IP blocklist | Listed addresses are refused | The whole customer workspace |
| Illizeo blocklist | Blocks set by Illizeo, including address ranges | Not editable by the customer |
An empty allowlist means everything passes. That is deliberate: without it, any workspace that never configured an IP would lock itself out. The IP filter is hardening, not the main guard — real protection comes from authentication.
Step-by-step #
-
Inventory your egress points #
Fixed office addresses, your VPN’s egress IPs, contractors who connect. Miss one and those people are locked out the moment you switch it on.
-
Add the addresses to the allowlist #
Settings → Manage Illizeo → Whitelisted IP. From the first saved entry, the rule becomes exclusive: anything not listed is refused.
-
Block specific addresses if needed #
The blocklist is there to shut out one identified address, independently of the allowlist.
-
Warn people before switching it on #
There is no simulation mode. The rule applies as soon as it is saved, to everyone, including you.
FAQ #
Can access be blocked by country?
No. There is no geographic filtering in Illizeo: no GeoIP database is queried and country codes are not a restriction criterion. The granularity is the IP address.
Can it be restricted per role?
No. The lists apply to the whole customer workspace, not to a role or an employee.
Is there a simulation mode?
No. Test from a connection outside the perimeter before extending the list, and keep access from an address that is already listed.
Does an unusual sign-in trigger an extra check?
No. Two-factor authentication, where enabled, applies to every sign-in for that role; it is not triggered by address or location.
What about remote work?
If everyone goes through your corporate VPN, allow its egress addresses — that is the easiest configuration to maintain. There is no temporary-exception request to approve.
What does not exist #
No country blocking and no GeoIP database. No restriction per role or per employee. No simulation mode. No conditional two-factor based on address or location. No temporary exception to request and approve. No “blocked sign-ins” report.
See MFA and password policies #
Strengthen authentication, beyond address filtering.
