How it works in a data room
The administrator enters a list of allowed IP addresses or ranges, usually supplied by each participant’s IT team. When someone tries to log in, the platform compares the incoming address with that list and blocks anything outside it, even with the right password. Restrictions can apply to the whole room or to specific groups, so a bank’s internal team might be locked to its corporate network while external lawyers sign in from anywhere with two-factor authentication. Blocked attempts are logged for review.
Why it matters in a deal
IP allowlisting is a blunt but strong control. A stolen password and a stolen second factor are both useless from an unknown network. It suits teams that already work through a VPN or a fixed office connection, for example government bodies, defense suppliers and some banks. It suits mobile users poorly, and a misconfigured range can lock out a whole bidder on the morning of a deadline, so test it before go-live and keep an exception process. It follows the same thinking as the principle of least privilege.
Example
A state-owned energy company in the United Arab Emirates opens a room for a minority stake sale. Its own staff can reach the room only from the corporate network, while international advisers are exempt and rely on app-based codes instead. On day two a consultant working from a client site is blocked, and the administrator adds a temporary range for one week. The UAE guide and the energy guide describe related requirements.