How it plays out on a deal
IP rules add a network condition to the login. Even with a valid password and second factor, a user outside the approved range cannot get in. Banks and regulated buyers sometimes require it for their own staff, and some sellers apply it to internal administrators.
It suits fixed teams and works less well for advisers who travel or work from home without a VPN. The practical question is whether rules can be set per group, so a strict rule for the seller's own administrators does not lock out every bidder.
What to check in a review or demo
- 1Whether IP rules can be set per group or only for the whole room.
- 2Whether blocked attempts show up in the audit log.
- 3Whether the rules apply to mobile apps and API access as well as the browser.
Read alongside
- Two-factor authentication (2FA)A login that needs a second proof of identity besides the password, such as a code from an authenticator app, a text message or a hardware key.
- Single sign-on (SSO)Logging in to the data room with an existing company identity, through a provider such as Microsoft Entra ID or Okta, usually over the SAML or OpenID Connect standards.
- Principle of least privilegeThe security rule that each user should get only the access needed for their task, for only as long as they need it.
- Audit trailThe room's running log of who did what and when.