Risky IP Protection and Enhanced Network Perimeter
- Services: IAM
- Release Date: May 06, 2026
Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) introduces Risky IP Protection and Enhanced Network Perimeters, a feature that helps administrators strengthen access controls for user sign-ins and OAuth token issuance by using dynamic risk signals from OCI Threat Intelligence, country-based location rules, and OCI Virtual Cloud Network (VCN) definitions.
Availability: This feature is currently available only for Oracle Internal tenancies. Customers interested in this capability should contact Oracle.
Highlights of this new feature include the following:
- Risky IP Protection: Use an Oracle-managed Risky IP Network Perimeter, powered by OCI Threat Intelligence, to help identify and restrict access from IPs associated with suspicious or malicious activity.
- Conditional Sign-In Controls: Deny access or require MFA when users attempt to sign in from risky IPs, selected countries, OCI VCNs, or configured network perimeters.
- Enhanced Network Perimeters: Define network perimeters using IP addresses, countries, OCI VCNs, VCN IP ranges, and exception lists.
- Location and VCN-Based Access: Create sign-in policies based on country or OCI VCN context, helping enforce geographic and private-network access requirements.
- OAuth Token Issuance Controls: Restrict application token issuance so tokens are issued only when the client request originates from an approved network perimeter.
- Trusted Exceptions: Add trusted IP addresses or ranges that should be excluded from perimeter evaluation.
- Improved Audit Visibility: Capture risky IP access and matched network perimeter details in audit events to help security teams investigate suspicious access.
To use this feature, administrators configure enhanced network perimeters in sign-on policy rules or application token issuance settings.