Allow OAuth clients
IP allow-listing forces applications and users to connect to Medallia Experience Cloud via known and approved IP addresses. For example, users viewing reports on Medallia Web reporting might be required to only use computers on the company's approved range of IP addresses. Valid users trying to sign in to Medallia Web reporting from a computer not in the company network are denied access.
OAuth clients can similarly be forced to only connect from the allowed IP addresses. This layer of security helps ensure that applications connect only from known addresses. For example, users of Medallia Mobile might be required to only connect from the company WiFi (which uses IP addresses in the allow-list).
To use IP address allow-listing:
-
Define all the company's allow-list addresses on the Logon Restrictions screen.
-
For each OAuth client that requires such access, turn on the Enforce IP allow-listing on access token refresh property on the Clients screen.
