Risky IP Protection and Enhanced Network Perimeter

  • Services: IAM
  • Release Date: May 06, 2026

Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) introduces Risky IP Protection and Enhanced Network Perimeters, a feature that helps administrators strengthen access controls for user sign-ins and OAuth token issuance by using dynamic risk signals from OCI Threat Intelligence, country-based location rules, and OCI Virtual Cloud Network (VCN) definitions.

Availability: This feature is currently available only for Oracle Internal tenancies. Customers interested in this capability should contact Oracle.

Highlights of this new feature include the following:

  • Risky IP Protection: Use an Oracle-managed Risky IP Network Perimeter, powered by OCI Threat Intelligence, to help identify and restrict access from IPs associated with suspicious or malicious activity.
  • Conditional Sign-In Controls: Deny access or require MFA when users attempt to sign in from risky IPs, selected countries, OCI VCNs, or configured network perimeters.
  • Enhanced Network Perimeters: Define network perimeters using IP addresses, countries, OCI VCNs, VCN IP ranges, and exception lists.
  • Location and VCN-Based Access: Create sign-in policies based on country or OCI VCN context, helping enforce geographic and private-network access requirements.
  • OAuth Token Issuance Controls: Restrict application token issuance so tokens are issued only when the client request originates from an approved network perimeter.
  • Trusted Exceptions: Add trusted IP addresses or ranges that should be excluded from perimeter evaluation.
  • Improved Audit Visibility: Capture risky IP access and matched network perimeter details in audit events to help security teams investigate suspicious access.

To use this feature, administrators configure enhanced network perimeters in sign-on policy rules or application token issuance settings.