What is the difference between profile login IP ranges, trusted IP ranges, and connected app IP relaxation?
Suggested answer
They sound alike and do three different jobs.
• Login IP ranges on a profile are a restriction: a user on that profile cannot log in from outside them at all.
• Trusted IP ranges under Network Access are a relaxation: a login from inside them does not trigger identity verification. Users outside them can still log in, they just have to verify.
• Connected app IP relaxation scopes an exception to a single application, so one integration can run from a datacentre that the profile restriction would otherwise block, without weakening anything for interactive users.
The mistake I look out for in reviews is someone adding a datacentre to trusted IP ranges to fix an integration that is being blocked by a profile login IP range. It looks plausible and does nothing, because the two controls are unrelated. The connected app setting is the right lever, and it has a middle option — enforce the restriction for the initial authorisation but relax it for token refresh — which is often the best fit when the first authorisation happens somewhere known.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.