2FA Bypassing Whitelisted IP's

Charlie Rivers-Bland November 3, 2021

Hi,

 

We are currently on a Premium plan for both Jira Cloud and Service Management.

 

We have everything locked down to a specific "office based IP address" so any external IP's cannot access our facilities.

 

However i was wondering if it was possible to bypass the IP Blocklist if a user had 2FA enabled.

We have users who may be using 4G to access the JIRA app when travelling. But due to a constant change in public IP address's it would be impossible to manage. (amending the allow list every day)

 

Thanks,

Charlie

2 answers

1 accepted

0 votes
Answer accepted
Andy Gladstone
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
January 18, 2022

@Charlie Rivers-Bland I am not sure if this is still an open issue for you, but I have done some research on it. 

2FA and IP Whitelisting are independent security features. Once there is an IP restriction on logins to your instance, it will reject any inbound traffic before your user can even attempt to login and reach a login in screen where 2FA would kick in. 

Andy Gladstone
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
January 20, 2022

@Charlie Rivers-Bland If my answer helped you, please mark it accepted to help other users find it when experiencing similar challenges.

Zeljko Milovanovic January 27, 2022

Hello @Andy Gladstone ,

we have similar issue, but question still remains: is it possible to allow mobile apps usage with IP Whitelisting in any way?

Andy Gladstone
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
January 27, 2022

@Zeljko Milovanovic if you enable IP Whitelisting, mobile app access will be restricted. There may be a solution if a company is using Atlassian Access where Mobile Device MAC addresses can be whitelisted, but I am not too familiar with that product to suggest or recommend.

Like Zeljko Milovanovic likes this
Zeljko Milovanovic January 27, 2022

Thank you, @Andy Gladstone

This means a lot! We will most certainly check this out.

Lena P September 12, 2023

@Andy Gladstone 

Do you know about any open change request for IP Whitelisting/ Confluence external user security? If we use IP whitelisting, how can we let guest access our confluence?
It would only be possible by listing their IP adresses, right? I would like to open a change request on this topic but am not sure how to proceed. I apreciate your help!

1 vote
Duane Kuroda September 18, 2023

I think the solution for this question was suggested (and would need more votes) on the Altassian jira for RFEs --> https://jira.atlassian.com/browse/ACCESS-1360

If I summarized it correctly, the ticket was to add an option to use MFA for users not on allowlist IPs (basically the mobile user use case)

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events