Knowledgebase Article
Category: Configuration | Module: OfficePro | Created: 9/5/2026 | Last Updated: 9/5/2026
IP authentication limits sign-in to the internet connections you name - typically the clinic itself, and the home connections of anyone who works remotely. Someone with a valid username, password and MFA code still cannot get in from anywhere else.
This is a strong control and it locks out the innocent as readily as the malicious. Read the warning at the end before switching it on.

Each row shows IP, Status, User / Description, Requested, Authorized and Actions.
When someone tries to sign in from an address that is not on the list, they are refused and the attempt is recorded as a request. Review these: if it is your own colleague working from a new place, click Authorize on that row and they can sign in. If you do not recognise it, leave it - an unauthorised row does nothing.
Most practices do not have a fixed address. Unless you pay your internet provider for a static IP, the clinic address can change on its own - after a power cut, a router restart, or an engineer visit - and when it changes, everybody is locked out at once, including you. Nobody can reach the Admin page to correct it, because the Admin page is behind the same check.
So:
For most practices, requiring multi-factor authentication gives most of the protection with none of the lockout risk. Consider that first, and add IP restriction only where the extra strictness is genuinely needed.