Console blocked by IP restriction when using M365 SSO

Status
Not open for further replies.

David_K

Bronze Partner
Basic Certified
Joined
Apr 3, 2019
Messages
198
Reaction score
27
Hello

On an hosted instance we're using the M365 SSO integration to connect to the admin console.

It seems that if you decide to restrict access to the console to your own WAN IP (from the Security menu), then M365 SSO does not work anymore.
So it's not possible to connect to the console anymore using SSO.


I wanted to use my normal admin credentials as an alternative access, but trying to connect via my usual SSO probably did trigger a 2 or 3 failed logins, and that would probably have blacklisted our own WAN IP. (which is too bad since I've just told the system to allow only our own WAN IP to connect)

I'll have now to restore a 3CX server for that reason.

I see 2 features to be added here :

  1. SSO should continue to work if you decide to restrict access per IP (or we should at least get a warning telling us what extra steps we need to take if using SSO)
  2. when you restrict access to the console to your own WAN IP, that IP should automatically be added to the whitelist so it'll never be blacklisted
    (I was almost sure I had our own IP manually whitelisted before, but maybe adding the console access IP restriction did remove it?)
 
It seems that if you decide to restrict access to the console to your own WAN IP (from the Security menu), then M365 SSO does not work anymore.
So it's not possible to connect to the console anymore using SSO.
What do mean?

the WAN IP you're connecting in from must be in the allowed list when you set up console restrictions regardless on how you're logging in to the management console.

When you set up IP restrictions for console it tells you, in red if your IP isnt in the list.

if you're locked out your hosted instance you can open a support ticket and get them to remove it for you.
 
Last edited by a moderator:
  • Like
Reactions: ChrisC_3CX
SSO should continue to work if you decide to restrict access per IP (or we should at least get a warning telling us what extra steps we need to take if using SSO)
It's as @kieferschild said, if you enable "Console Restrictions" then you'll have to make sure that the IP's logging into the system either via SSO or using the 3CX PBX credentials are added to the whitelist.

when you restrict access to the console to your own WAN IP, that IP should automatically be added to the whitelist so it'll never be blacklisted
That may have been handy but what if you are configuring the PBX from a different IP that you won't be using ever again? The current design is that it automatically whitelists all local IP ranges. As @kieferschild said, it will display a warning message in red to let you know if the public IP you're using is not in the list so it should be fairly easy to notice before hitting OK:
1637845469407.png


To help you regain access, we might need a bit more information, is the 3CX PBX at hand hosted by 3CX?
 
Last edited by a moderator:
It was not an "hosted by 3CX" but hosted by ourselves.

After having restored the server, I confirm that our IP was already in the whitelist BEFORE adding the "Console restrictions". And still I was getting rejected when trying to connect using the "old" way with a message telling me incorrect password, please contact the administrator.

Also the SSO was not working at all anymore.
As soon as you click on the Microsoft icon on the 3CX login page, the screen blinks once, and stays on the login page. Like if it was unable to redirect to the Microsoft application.
I think that could be a restriction because during the process Microsoft does not use our own WAN IP to communicate with our 3CX console to allow the SSO
 
Just to make sure I understand, does MS365 SSO work now or not?

If not, remember that you need these options checked in your MS365 app registration:
1637851859295.png
 
I've restored to a version where IP "Console Restriction" was not activated. So yes SSO is working again.

I won't reactivate it to get the same problem again.

In the app registration, "ID tokens" is checked but I was not aware I had to check "Access tokens".
I follwed the tutorial from the 3CX console that says :

1637852206753.png
It says to enable "ID tokens" but does not tell about "Access tokens"
 
I believe "Access Tokens" are already enabled by default, so there is no point to say "enable it" if it is already enabled.
It also does not say "disable it", so generally we expect the rest to be left with the default values.
 
On my side "Access Tokens" is not enabled by default when I add a new app registration. I have dozen of other registered apps, and none has this checked.
Since I don't know what this does, and if it solves or not the issue of SSO not working with IP "Console Restriction", then I prefer not to check it for now
 
On my side "Access Tokens" is not enabled by default when I add a new app registration. I have dozen of other registered apps, and none has this checked.
Since I don't know what this does, and if it solves or not the issue of SSO not working with IP "Console Restriction", then I prefer not to check it for now
You are right, so technically it can remain off.
 
If you have a trial server somewhere you can try to see if you get the same than me :

1/ configure SSO connexion
2/ when you have SSO working, add IP Console Restriction (with your own WAN IP)
3/ now SSO not working anymore

I did this on a production server and I don't have a trial server up and ready.
 
Not sure what is happening, but we can't replicate it.

What I am doing:

My settings:
1637854973652.png


What happens not when I try to access from a different Public IP:
1637855077464.gif


What happens why I try to access from the IP I have allowed:
1637855340119.gif


Am I doing something different?

[EDIT]
Could it be some conflicting rule in your IP Blacklist?
 
  • Like
Reactions: RCT-CP
And make sure you've not got conditional access set up in Office 365 to restrict logins to certain IPs. And If you have, add your 3CX.
 
Our WAN IP is whitelisted (so it should never been blacklisted I suppose)

Have you seen what's hapening when try to connect from another IP? The screen just blinks, no error message, just a blink. And I think the server still takes this as a incorrect login from your M365 account.

But I get this "blink" even when we connect using our own WAN IP (that is in the list of allowed IPs in Console Restrictions)

Yes we have conditional access setup in O365 with only 1 restriction : force MFA usage if we do not connect from behind our WAN IP. (so no MFA restrictions since I'm now behind our WAN IP)
 
Have you seen what's hapening when try to connect from another IP? The screen just blinks, no error message, just a blink. And I think the server still takes this as a incorrect login from your M365 account.
I -double-checked that but no, it doesn't take it as an incorrect login to cause the IP to become blacklisted. This "blink" is expected in this scenario, when MC IP Restrictions are on.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru