Access control is an essential feature for ensuring that your Umbraco Cloud site is secure and only accessible to the intended audience. This article covers the available methods for restricting site access, including internal network access control and interaction with external services like Cloudflare, as well as upcoming enhancements to improve access security.
Restricting Access to Internal Networks
To limit access to your Umbraco site so that it is only available from your internal network (and not visible to the general public), you can utilize IP whitelisting. Configuring IP whitelisting ensures that:
Visitors from whitelisted IP addresses can access the site content.
Visitors from non-whitelisted IP addresses will be blocked and shown a basic login form, preventing any unauthorized access to your site content.
This form of restriction is effective for maintaining strict access control to your site.
Integrating Access Control with External Services (Cloudflare)
Currently, edge-layer access restrictions such as IP allow-listing or mutual TLS (mTLS) that strictly limit traffic to your Cloudflare account are not available in Umbraco Cloud. However, there are alternative features to help control network access:
Use the Public Access feature to require basic authentication, with an optional bypass for specific IP addresses.
While these features do not constitute edge-layer restrictions, they still provide a level of flexibility and control for managing access. Future enhancements like edge IP firewalling are in development as part of a broader infrastructure rework. This will provide a more robust and comprehensive solution for edge-layer access control.
Summary
Umbraco Cloud currently supports access restrictions through:
IP whitelisting for internal network control.
Public Access features for additional network limitations.
While edge-layer restrictions with external services like Cloudflare are not yet available, these options provide effective interim measures. Keep an eye out for future updates on edge IP firewalling for enhanced security.
Related Topics
Setting up Public Access in Umbraco
Managing IP restrictions in cloud environments
Roadmap for Umbraco security enhancements
