Add Tenant Access
By default, all IP addresses can access the SAS Customer Intelligence 360 user interface and make API calls to the tenant's gateway. Use the Tenant Access settings to limit the IP addresses that are permitted to make these actions.
To add access to a tenant:
- From the navigation bar, click
Administration
General Settings and select External Access
Tenant Access. - In the IP
Range(s) drop-down menu, specify whether the IP addresses apply to
the User interface only, the API
gateway only, or the User interface and API
gateway. Specify a range of IP addresses and click
Add.
IMPORTANT Include your external IP address in the range of allowed IP addresses for the user interface to ensure that you do not lose access to the user interface.
If you accidentally block your users from using the SAS Customer Intelligence 360 user interface, a SAS Customer Intelligence 360 administrator must send a request to SAS Technical Support to temporarily disable the allowlist. Your administrator – a user who is assigned the Super Admin, Configuration Admin, or the Discover Admin role – must make this request in writing through a SAS Technical Support ticket and provide their full contact information so that SAS Technical Support can verify their identity.
SAS Technical Support will disable the allowlist for 24 hours so that the administrator can restore access to the user interface to your users. Once 24 hours have passed, the allowlist is enabled again.
Use the following best practices when you specify the range of IP addresses:
- You can add only one range of IP addresses at a time.
- Use CIDR notation to specify the range of IP addresses (for example, 192.186.12.0/24).
- You cannot add a duplicate IP
range. However, if you select User interface and API
gateway and only one of the lists contains the duplicate IP
address range, the range of IP addresses is added to the list that does not
contain the duplicate IP addresses.
For example, 192.186.12.0/24 is listed as an allowed IP address range for the tenant's user interface only. If you select User interface and add 192.186.12.0/24, you will receive an error. If you select User interface and API gateway and add 192.186.12.0/24, the range of IP addresses is added to the list of allowed ranges for the API gateway. The list of allowed ranges for the user interface remains the same.
- You can add the same IP range with a different CIDR notation (for example, 192.186.12.0/12).
- The Allowed user interface IP range(s) field lists the range of IP addresses that are allowed to access the tenant's user interface. The IP address ranges are arranged in ascending order.
- The Allowed API gateway IP range(s) field lists the range of IP addresses that are allowed to access the tenant's API gateway. The IP address ranges are arranged in ascending order.
- Click
to save your changes. The new settings apply to users who sign in after you save your updates. Your current access is not affected by the changes that you make in the same session.