ZTCA Configuration: Restrict DocuSign sign-ins to trusted IPs using Entra Conditional Access
ID: 46e9015b-9dae-57c0-b760-d5aa617bb685
STIX ID: report--46e9015b-9dae-57c0-b760-d5aa617bb685
Feed Name: ThreatLocker Blog
This guide describes how to restrict DocuSign sign‑ins to trusted IP addresses using Microsoft Entra ID Conditional Access: create a Named Location for static trusted IP(s), build a Conditional Access policy that targets DocuSign and blocks access from locations outside that named list (excluding break‑glass/service accounts), validate in Report‑only mode using sign‑in logs and the What If tool, then enable the policy once testing confirms correct behavior; it also lists prerequisites and limitations such as requiring DocuSign SAML SSO with claimed domains and static egress IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
