IP Restriction | Manage your Zoho account

Secure account access using IP address restriction

IP address restriction lets you control account access based on the network you're signing in from. When it's configured, a sign-in attempt is allowed or denied depending on whether it comes from an IP address you've added to the restriction. You can set this up for your own individual account, or, if you manage an organization, enforce it for all your users.

Configuring IP restriction: account vs. organization

Secure your own account
Enforce for organization
Secure your own account
To increase the security of your account, you can set up IP address restriction to allow access only from trusted networks. You can configure this restriction yourself from accounts.zoho.com.

Refer to the section IP restriction in detail to learn about it, and Set up IP address restriction for your account to configure it.
Enforce for organization
If you're an administrator, you can enforce IP restriction for a required group of users in your organization through security policies. You can configure this restriction in the apps providing user management functions (listed below), not in accounts.zoho.com. We recommend configuring it through Zoho Directory:
  1. Zoho Directory (reccommended)
    1. Security 1.0
    2. Security 2.0
  2. Zoho One
    1. Security 1.0
    2. Security 2.0
  3. Zoho Mail
  4. Zoho CRM

IP restriction in detail

What is an IP address

Internet Protocol address (IP address) is a unique series of numbers used to identify a device or a network. If you're connected to a Wi-Fi network, that network has its own IP address, and any application you access over it can identify the IP address you're connecting from.

Restriction mode

When you set up IP address restriction, you choose one of two modes:
  1. Allow added IP addresses: sign-in is allowed only from the IP addresses you add. Every other IP address is denied.
  2. Deny added IP addresses: sign-in is denied from the IP addresses you add. Every other IP address is allowed.
You choose this mode the first time you set up the restriction, and it applies to every IP group you add afterward. To switch modes later, you need to delete all currently added IP groups and set up the restriction again.

IP address groups

You add IP addresses as named groups, for example, Office IP or Home IP. Each group can contain multiple IP addresses, including a mix of different types, and has its own restriction scope and expiration. You can add as many groups as you need under the same restriction, and each one is edited, deleted, or reviewed as a single unit.


IP address types

Within a group, you can add an IP address in any of the following ways:
  1. Current IP: the IP address you're currently signed in from.
  2. Individual IP: a single static IP address.
  3. IP Range: a range of IP addresses, specified with a from address and a to address.
  4. CIDR Block: a block of IP addresses specified using CIDR notation (for example, 203.0.113.0/24). Supported prefixes range from /0 to /32.
Warning
Warning: Make sure the IP addresses you add are static gateway IP addresses. Dynamic IP addresses change over time, and adding one could lock you out of your account.

Restriction scope

For each IP group, choose which sign-in paths the restriction applies to:
  1. Browser and app sign-ins: covers access from browsers, Zoho apps, and connected apps.
  2. POP/IMAP clients: covers access by POP/IMAP-based third-party apps and extensions, such as third-party mail and calendar clients.
You can select one or both. Selecting POP/IMAP clients as well is recommended, so the restriction also covers sign-ins from third-party mail and calendar apps, in addition to browsers and connected apps.

Expiration

You can optionally set an expiration date and time for each IP group. Once a group's expiration passes, it's automatically disabled and no longer applies to sign-in attempts.

Set up IP address restriction for your account

Set up IP address restriction
  1. Sign in to accounts.zoho.com.
  2. Under Security, go to Allowed IP Address.
  3. Click Set up IP Restriction.
  4. Select a restriction mode: Allow added IP addresses or Deny added IP addresses.
    Warning: You can't change the restriction mode later without deleting all the IP groups you've added and setting up the restriction again from the start.
  5. Click Continue.
  6. In the IP Name field, enter a name for this IP group (for example, Office IP).
  7. From the IP Type dropdown, select an IP type (Current IP, Individual IP, IP Range, or CIDR Block), then enter the required address details. To add more addresses to the same group, click +.
  8. Click Next.
  9. Under Apply this restriction to, select the required restriction scope: Browser and app sign-ins, POP/IMAP clients, or both.
  10. (Optional) Enable the Set expiration toggle, then specify the expiration date and time.
  11. Click Enable IP Restriction.

Add another IP group
You can add more IP groups to the same restriction, for example, a separate Home IP group alongside an existing Office IP group. Every group you add follows the same restriction mode.
  1. Under IP Address Restriction, click + Set up IP Restriction.
  2. Follow steps 6 through 11 of Set up IP address restriction to name and configure the new group.
Change the restriction mode
WarningWarning: Changing the restriction mode deletes every IP group you've currently added. You'll need to add them again after switching.
  1. Under IP Address Restriction, click change restriction mode.
  2. Select the new mode: Allow added IP addresses or Deny added IP addresses.
  3. Click Continue.

Edit or remove an IP group
To view a group's name, added IP addresses, applied scope, and expiration, click the group under IP Address Restriction.
  1. To edit a group, click its Edit icon, or click Edit IP Address Group in the group's details.
  2. To delete a group, click its Delete icon, or click Delete IP Address Group in the group's details.


What to do if you get locked out of your account

If you're not able to sign in because of an IP restriction, refer to this troubleshooting article.
  1. If you set up the restriction yourself and have account recovery options available, you can remove or reconfigure it without signing in. Refer to How to remove IP restriction.
  2. If the restriction is enforced by your organization, contact your administrator to help you recover access.
If you still can't resolve the issue, contact support@zohoaccounts.com. Our support team disables the IP restriction after verifying your identity. You can write to us from any email address, but be sure to mention your account's email address in the message.