MFA public ip exclusion list

I really second this. As a Service Provider, the inability to filter on client public IP poses a security threat to us as we need to disable 2FA for known public IP addresses of our customers, not for their private range. If we create an exclusion for the range 192.168.1.0/24 because a customer has this on his subnet, it would allow anyone to bypass the MFA by just having the same subnet range on their computer..
 
Back
Top