IP Management
Overview
The IP Management page, found under Tenant Settings, gives you a single place to manage the network-related signals that Cisco Identity Intelligence can use when evaluating Checks or to tag known-network activity in relevant activity and network logs. Instead of maintaining separate lists inside individual check settings, you can define your organization's known networks, trusted internet service providers (ISPs), and restricted territories once, then reference them from any Check that supports these settings.

Consolidating this configuration in one place makes it easier to keep your network context accurate and consistent, which reduces false positives on location and network-based Checks such as Impossible Travel, Activity from Untrustworthy ISP, and Access from Denied Territories.
Adding items via the IP Management pages does not automatically change any Check's behavior. Items you add to Trusted Networks or Trusted ISPs must still be enabled on each relevant Check's settings page before they affect that Check's results. Only Denied Territories are applied to the check automatically. See the Applying IP Management data to Checks section below for more details.
The IP Management settings page is organized into three tabs:

Networks
Many organizations maintain a list of known, approved networks for their organization. Trusted Networks let you define named, known network locations for your organization - for example, Corporate HQ, London Office, or Partner X Datacenter - along with the IP addresses or CIDR ranges that belong to each one. Trusted Networks can be added to Identity Intelligence directly, or ingested via Named Locations from Entra.
Use Trusted Networks to tell Identity Intelligence which IP ranges represent expected, low-risk locations. Checks that reference Trusted Networks use this information to avoid flagging normal activity, such as an employee signing in from an office network, as suspicious.
Only add networks and ISPs that are approved and trusted for your organization, NOT known malicious networks. If you enable a check's settings to exclude known-good IPs from the detection logic, any network added to these lists will be excluded from that check's logic, including any malicious networks that have been incorrectly added.
Managing entries
Adding IPs
There are two ways that Trusted IPs and IP ranges can be added to Identity Intelligence - manually one by one, or via bulk upload. First, select Networks from the drop down and make sure you are on the IP CIDR tab to add a new named network. Then decide if you would like to manually enter IP addresses, or upload a list and follow the respective instructions found below.

To manually enter one or more IP addresses or CIDR ranges:
Select + Network. A new row will be added to the table
Under the Name column, enter an easily recognizable name for the IP address/range in the blank field [eg: New York HQ]. This name will be used throughout the UI to identify activity associated with this network
Under the IP/CIDR column, enter the desired IP address or range in the blank field
A network can have multiple IP ranges associated under the same network "name" if needed. To add multiple IPs to the same known network identifier, select the + IP / CIDR button below the previously populated field
When you are finished entering IPs, select Save to store your changes
[RECOMMENDED APPROACH] To upload a list of IP addresses or CIDR ranges:
Select the Upload File button and select either Merge upload with existing networks to add new IPs to an existing network from the list, or Override existing networks with uploaded file to remove any existing networks from the list and create a new list based on the uploaded list
Upload the desired list of networks by dragging and dropping your file into the designated area, or selecting the designated area to find and choose the file
The uploaded file MUST use the CIDR JSON format, with one location and description pair per line as shown in the example below. Download the following JSON sample file available here and modify it with your own known IP addresses and location tags:
Select Upload File to confirm the upload
The upload will begin to process in the background. Identity Intelligence will start validating the file, merge the results (if that option was selected), and the table will be refreshed once the upload modal is closed. If any entries in the file are invalid (for example, a malformed CIDR range), Identity Intelligence will skips these values and display a warning summarizing what items were skipped
The platform does not support a JSON array format (wrapping all records in [ ]). Each line must be its own valid JSON object.
There is a limit of 870kB for a given upload file. If your file is bigger than the allowed size, use the "Merge upload with existing networks" option to upload your file in parts.
Modifying IP addresses
To modify or remove an IP address or IP range, select the Pencil icon in the Action column for the desired IP. Modify an individual IP address or range as needed or delete that value by selecting the Trash button icon found in either the Action column of the associated row or the specific value in the IP/CIDR column. Select Save to store any changes made.
If bulk modifications are needed, you can export a JSON file of the current list of trusted networks, in the correct IP CIDR format, using the Download button. You can modify this file and then re-upload it after to quickly modify several IPs in the list at once.
You can also select the Restore Default button to remove any custom entries from the list and revert back to the default list of Trusted Networks. (Default list is blank)
Named Locations
If you use Microsoft Entra ID, it allows your organization to define its own network locations (Named Locations). Those locations will also appear in the Named Locations tab under the Trusted Networks view.

Named Locations are sourced from your identity provider and are read-only in Identity Intelligence, meaning they cannot be modified or removed within Identity Intelligence. To make changes, update them via your identity provider directly.
ISP Domains
Trusted ISPs identifies internet service providers (ISPs) commonly used by your employees, partners, or contractors that you consider low-risk, such as a residential broadband provider frequently used for remote work.
Checks that evaluate the ISP associated with an activity's IP address, such as IP Threat Detected, use this list to distinguish recognized, everyday providers from anonymizers, hosting providers, or other high-risk network sources. Identity Intelligence includes a default list of commonly trusted ISPs and network-obfuscation providers out of the box, while allowing you to add your own domains based on your organization's need. Default and custom entries are labeled accordingly, so you can easily distinguish which ISPs your organization has added. You can edit or remove default entries using the same steps described below, or restore the default list at any time using the Restore Default List button.
Managing entries
Select ISP Domains from the drop down on the IP Management page

Select + Internet Service Provider. A new row will be added to the table
Under the Name column, enter the ISP Domain value in the blank field. The domain should be the value that comes after, but not including the
@. For example, a correct ISP domain iscisco.com, not@cisco.comAfter you have entered your desired ISPs, select Save to store your changes
To modify or remove a domain, select the Pencil icon in the Action column for the desired domain. Modify an individual domain as needed or delete that value by selecting the Trash button icon found in the Action column of the associated row. You can also select Restore Default to remove all custom ISP domains from the list and revert to the default Identity Intelligence list. Select Save to store any changes made.

Territories
Restricted Territories defines the countries or regions that your organization considers untrusted, sanctioned, or otherwise restricted for access.
Checks such as Access from Denied Countries use this list to flag or fail activity originating from a restricted territory. Identity Intelligence provides a default list of restricted territories based on the Office of Foreign Assets Control's guidelines. Default entries are labeled accordingly, so you can tell them apart from custom territories your organization has added. You can edit or remove default entries, or restore the default list at any time.

Managing entries
Select Territories from the drop-down menu
Select the + Restricted Territory button to add a country or region/territory. A new row will be added to the table
Select the desired country from the drop down menu in the Country column. If needed and available, select a region within that country from the Region column
To modify or remove a country/territroy, select the Pencil icon in the Action column for the desired location. Modify an individual country or territory as needed, or delete that value by selecting the Trash button icon found in the Action column of the associated row. You can also select Restore Default to remove all custom countries/territories from the list and revert to the default Identity Intelligence list. Select Save to store any changes made.
Applying IP Management data to Checks
The Networks and ISP Domain pages create a centralized "approved" source of data for these various lists; however, it still allows the flexibility to customize the settings of a Check as needed rather than deciding automatically which checks will or won't use specific values. Check settings are still managed manually, on a check by check basis - meaning you can exclude Known Good IPs on some checks but not others, or add an ISP domain to the ignore list on one check but not another, depending on your organization's needs, concerns and risk tolerance levels.
Note: Restricted Territory settings behave differently. These settings only apply to the Access from Denied Territories check and therefore are automatically applied to the check. They cannot be modified via the Check Settings directly. To apply a Trusted Network or Trusted ISP Domain to a given check:
Navigate to the relevant check and expand the Check Settings found on the right side of the page - Checks that can be modified to ignore Trusted Networks will have a setting to "Exclude Good Known IPs". Checks that can be modified to ignored Trusted ISP Domains will have an Ignore list
Select Edit. A modal will appear that allows you to configure the respective settings accordingly - Toggle on the "Exclude Good Known IPs" setting. For an ignore list, select Add and start typing in an ISP Domain sourced from the centralized list configured in the IP Management section
Select Save to store the changes made in the check's settings
To add additional IPs or Domains, navigate to back to the relevant IP Management page, make the necessary changes and then return to the check to apply the setting as needed.

Last updated