Restricting administrative access by IP address
If your administrators only ever work from two places, say so.
How it works
Admin → Security holds an allow-list of IP addresses and ranges. When it is populated, administrative screens refuse connections from anywhere else — even with a correct password and a valid second factor.
Before you enable it
Confirm your office IP is static. A dynamic residential connection will lock you out at the next router restart. Add a fallback: a range from your VPN, or leave one administrator account exempt.
What it does not protect
Staff and client portals stay open — they have to be. This is a control for the administrative surface only.