Discover how TIMIFY IP Whitelisting helps multi-location organisations restrict employee access to approved networks, strengthen security controls, and support compliance across every location.

Passwords, two-factor authentication and single sign-on help verify who is attempting to access a business system. But for organisations with strict security policies, identity is only part of the equation. They may also need to control where employees can authenticate from.
This becomes more difficult as an organisation grows. Without a consistent network-based policy, users may be able to access business-critical scheduling tools from home networks, public Wi-Fi or other unapproved environments.
TIMIFY’s IP Whitelisting gives Enterprise organisations an additional layer of location-based access control. Administrators can define the office networks from which employees are permitted to authenticate, apply separate rules to central and branch teams, and review blocked access attempts in the *Branch Manager Activity Log.
The result is a clearer, more consistent way to support corporate security and compliance policies across every location.
*TIMIFY Branch Manager is the central platform for setting up, managing and monitoring multiple business locations. In the context of IP Whitelisting, Branch Manager gives authorised administrators one central location to manage the approved network rules for headquarters and branch users.

IP Whitelisting, also known as IP allowlisting, is an access-control method that permits authentication only from approved IP addresses or network ranges. The organisation defines which network addresses are trusted and denies access from addresses outside that list.
Each office, store or corporate VPN typically connects to the internet through one or more public IP addresses. By adding those addresses to an approved list, an organisation can allow employees to access TIMIFY through its authorised networks while blocking authentication from other locations.
For example, an employee connected to the network of an approved branch could authenticate as usual. The same employee attempting to log in through a home connection or public network would be denied access.
IP Whitelisting is not intended to replace passwords, two-factor authentication or SSO. Instead, it adds a network-based condition to the authentication process: the user must present valid credentials and connect from an approved IP address.
This reflects a broader identity and access management principle: organisations should consider not only who needs access, but also the conditions under which access should be granted.
As businesses expand, maintaining consistent access policies becomes harder. Each new office, branch, store or regional team introduces another environment from which employees may need to use company systems.
IP Whitelisting helps organisations introduce one clear rule: access is permitted through approved business networks and blocked everywhere else.
A valid password does not show whether someone is working from an approved office, a personal device at home or a public connection.
Adding an IP restriction helps reduce access from environments that fall outside the organisation’s security policy. It can be particularly valuable when employees handle sensitive customer, resource, or operational information.
Manually communicating access expectations is not the same as technically enforcing them.
With IP Whitelisting, an approved network policy can be applied across all relevant branches in a Branch Manager account. This gives central IT and operations teams consistent control rather than relying on employees to decide whether a connection is appropriate.
IP Whitelisting does not, by itself, guarantee compliance with a particular regulation or certification. It can, however, support internal controls that require employees to access business systems only from managed environments.
The associated audit trail also gives administrators greater visibility into blocked login attempts and changes to the IP configuration. That evidence can support internal reviews, incident investigations and compliance reporting.

IP Whitelisting is available for Enterprise organisations using a Branch Manager. Our Team first activates the feature for your account. After activation, the organisation’s Branch Manager administrator can manage the approved addresses from Settings → Security.
Organisations do not always want to apply the same policy to every type of user.
TIMIFY therefore provides separate configurations for:
The two lists operate independently. An organisation could restrict Branch Manager to its headquarters network while allowing branch employees to access the Web App without an IP restriction. Alternatively, it could enable both lists and use different approved networks for central and branch teams.
Administrators enter one approved IPv4 address or CIDR range per line. A single address can represent one network connection, while CIDR notation can be used to cover a wider office subnet.
The current configuration supports:
The form validates entries before saving. It prevents administrators from enabling the restriction without entering an approved address, rejects invalid or overly broad ranges, and blocks the allow-all range 0.0.0.0/0. Duplicate entries are removed automatically.
Because the Web App configuration is account-wide, all branches within the same Branch Manager account share one approved list. Organisations with multiple sites can add each branch network or consolidate suitable addresses into CIDR ranges.
A new IP configuration applies as soon as it is saved.
Employees whose current address remains approved can continue working without interruption. Someone whose address has been removed is stopped on their next action and must authenticate again through an approved network. A newly added network can be used immediately.
This approach avoids unnecessarily logging out everyone whenever an administrator adjusts the list. The IP check continues to run during use, independently of the standard session duration.
For additional protection around unattended sessions, organisations can combine IP Whitelisting with TIMIFY’s session length and idle log-out controls.
IP Whitelisting adds a separate control rather than replacing the organisation’s authentication method.
For standard single-account authentication, TIMIFY first validates the user’s credentials and then checks their IP address. A user on an unapproved network is blocked before progressing to two-factor authentication. Users authenticating through supported SSO methods are subject to the same underlying IP restriction after returning to TIMIFY from their identity provider.
Organisations can therefore combine location-based access rules with two-factor authentication to verify both the user’s identity and their network context.

The Branch Manager Activity Log records unsuccessful authentication attempts from IP addresses that are not on the approved list. Each event can include the user’s identity, attempted IP address, timestamp and an indicator showing whether the attempt concerned Branch Manager or the Web App.
Administrators can filter the log using two separate event categories:
This separation makes it easier to distinguish between a user attempting to authenticate from the wrong place and an administrator changing the approved network policy. Successful authentication from approved networks is not added to the IP Whitelisting log.
A multi-location organisation may allow Branch Manager access only through its headquarters network or an approved corporate VPN. Central teams can manage global settings, services and resources without making the same administrative access available from personal connections.
A retailer or service provider can add the public network addresses used across its stores, branches or consultation locations. Employees can access the Web App while working on site, while attempts from networks outside the approved list are blocked.
Organisations with strict internal security requirements can use IP Whitelisting to support policies that restrict access to corporate offices or managed VPN connections.
HR departments may use scheduling tools for interviews, internal consultations or employee services. Restricting staff authentication to managed workplace networks adds another control around access to this operational data.
Technology or service partners with access to a TIMIFY account can be required to connect through their approved corporate network rather than through arbitrary external connections.

IP Whitelisting is most effective when the approved network information is prepared and verified in advance.
Before activation, involve the team responsible for network infrastructure and confirm:
IP Whitelisting is best suited to organisations with fixed office networks or a managed VPN. A highly mobile workforce may need a VPN or another predictable network route before the restriction is practical.
Administrators should also check that their own current connection is included. TIMIFY prevents an enabled configuration from being saved without any addresses, but an administrator could still exclude the network they are currently using.
If a configuration error results in a lockout, a TIMIFY Account Manager can grant time-limited temporary access to a specific user. This break-glass process lets the user correct the configuration without deleting the existing IP list. The temporary bypass expires automatically.
Disabling IP Whitelisting for one of the scopes permanently deletes the saved IP list for that scope. The configuration would need to be entered again if the restriction is re-enabled later. Disabling the Branch Manager list does not affect the separate branch list, and vice versa.
Multi-location organisations need security policies that remain consistent as teams, branches and operational complexity grow.
TIMIFY IP Whitelisting helps ensure that employees authenticate through approved business networks. Separate controls for Branch Manager and branch access give organisations the flexibility to protect headquarters and local teams differently, while the Activity Log provides visibility into blocked attempts and administrative changes.
Combined with precise employee access permissions, SSO, two-factor authentication and session controls, IP Whitelisting becomes part of a layered approach to protecting enterprise scheduling operations.
Book a demo to explore our enterprise scheduling and access-control capabilities.

Konstantin is CRM Manager at TIMIFY, where he oversees all outbound communication with customers across multiple channels. With a keen eye for automation and a strong passion for emerging technologies, he constantly experiments with customer journey flows to optimise engagement and retention. Konstantin thrives at the intersection of data, technology, and human connection—always seeking smarter, more personalised ways to connect with users and enhance their experience.


