Control login access at the user level by specifying a range of
allowed IP addresses on a user’s profile. When you define IP address restrictions for a
profile, a login from any other IP address is denied.
| Available in: Salesforce Classic and Lightning Experience |
| Available in: Professional, Enterprise,
Performance, Unlimited, Developer, and Database.com
Editions |
| Custom Profiles available in: Professional, Enterprise,
Performance, Unlimited, and Developer
Editions |
| To view login IP ranges: |
“View Setup and Configuration” |
| To edit and delete login IP ranges: |
“Manage Profiles and Permission Sets” |
- From Setup, enter Profiles in the Quick Find box, then
select Profiles.
- Select a profile and click its name.
- In the profile overview page, click Login IP Ranges.
- Specify allowed IP addresses for the profile.
- To add a range of IP addresses from which users can log in, click Add IP
Ranges. Enter a valid IP address in the IP Start
Address and a higher-numbered IP address in the IP End
Address field. To allow logins from only a single IP address, enter the
same address in both fields.
- To edit or remove ranges, click Edit or
Delete for that range.
- The IP addresses in a range must be either IPv4 or IPv6. In
ranges, IPv4 addresses exist in the IPv4-mapped IPv6 address space ::ffff:0:0 to ::ffff:ffff:ffff, where ::ffff:0:0 is
0.0.0.0 and ::ffff:ffff:ffff is 255.255.255.255. A
range can’t include IP addresses both inside and outside of the IPv4-mapped IPv6
address space. Ranges like 255.255.255.255 to ::1:0:0:0 or :: to
::1:0:0:0 aren’t allowed.
- Partner User profiles are limited to five IP addresses. To increase this limit,
contact Salesforce.
- The
Salesforce Classic Mobile app can bypass IP ranges
that are defined for profiles. Salesforce Classic Mobile initiates a secure connection
to Salesforce over the mobile
carrier’s network. However, the mobile carrier’s IP addresses can be
outside of the IP ranges allowed for the user’s profile. To prevent bypassing
IP definitions on a profile, disable
Salesforce Classic Mobile for that
user.
- Optionally enter a description for the range. If you maintain multiple ranges, use the
Description field to provide details, like which part of your network corresponds to this
range.
You can further restrict access to Salesforce to only those IPs in Login IP Ranges. To
enable this option, in Setup, enter Session Settings in the
Quick Find box, then select Session Settings and
select Enforce login IP ranges on every request. This option affects all
user profiles that have login IP restrictions.