logo

How to restrict CyberDrain Improved Partner Portal (CIPP) to specific IP addresses using Conditional Access

ID: 9ea9ea7b-6e99-5107-810e-673edb90e8d1

STIX ID: report--9ea9ea7b-6e99-5107-810e-673edb90e8d1

Feed Name: ThreatLocker Blog

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

This guidance explains how MSPs can reduce risk by restricting access to the CyberDrain Improved Partner Portal (CIPP) using Microsoft Entra ID Conditional Access and CIPP's built-in IP allowlist. It provides prerequisites and step-by-step instructions to create a Named Location and CA policies: Part A (restrict technician UI by IP), Part B (enforce MFA every sign-in for the CIPP service account with no trusted location exclusions), Part C (configure per-client CIPP-API allowed IP ranges), and Part D (add MSP tenant exclusions in client CA policies for GDAP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.