- Erste Schritte
- Datensicherheit und Compliance
- Datensicherheit und Compliance
- Verschlüsselung
- Zertifikat
- Funktionale Sicherheit
- Konfigurieren der Firewall für Test Cloud
- Legacy – Konfigurieren der Firewall für Test Cloud
- Konfigurieren der Firewall für Test Cloud – Öffentlicher Sektor
- Konfigurieren der Firewall für Test Cloud Dedicated
- Funktionsveröffentlichung
- Hochverfügbarkeits- und Notfallwiederherstellungsstrategie
- Organisationen
- Authentifizierung und Sicherheit
- Lizenzierung
- Über die Lizenzierung
- Einheitliche Preise: Lizenzierungsplan-Framework
- Aktivieren Ihrer Enterprise-Lizenz
- Migrieren von Test Suite zu Test Cloud
- Lizenzmigration
- Zuweisen von Lizenzen zu Mandanten
- Zuweisen von Benutzerlizenzen
- Freigegeben von Benutzerlizenzen
- Überwachung der Lizenzzuweisung
- Lizenzüberzuweisung
- Lizenzierungsbenachrichtigungen
- Benutzerlizenzverwaltung
- Mandanten und Dienste
- Konten und Rollen
- AI Trust Layer
- Über AI Trust Layer
- Überprüfung der Nutzungszusammenfassung
- Anzeigen von Überwachungsprotokollen
- Verwalten von AI Trust Layer-Richtlinien
- PII-Maskierung
- Verwalten von Autopilot for Everyone
- Konfigurieren von LLMs
- Einschränken von LLM-Aufrufen auf Ihre eigenen Modelle
- Konfigurieren von OpenTelemetry
- Steuern von kontextbezogenen Daten für GenAI-Funktionen
- Externe Anwendungen
- Benachrichtigungen
- Protokollierung
- Datenexport
- Tests in Ihrer Organisation
- Fehlersuche und ‑behebung
- Migration zur Test Cloud
Legacy IP ranges for Test Cloud services, provided for reference during the transition to the unified IP range configuration.
Allgemeine Netzwerkkonfiguration und Firewall-Informationen finden Sie unter Konfigurieren der Firewall
Hinweis zu veralteter Eigenschaft – Aktion erforderlich
The IP ranges listed on this page are being deprecated. As of June 16, 2026, new unified IP ranges have been published and must be added to your allowlist alongside these ranges. Starting September 16, 2026, the IP ranges on this page will be gradually phased out. For specific dates, see the Timeline in the Deprecation notice section below.
Vor dem Enddatum des Übergangs: Behalten Sie diese IP-Bereiche in Ihrer Firewall-Konfiguration bei und fügen Sie die neuen einheitlichen IP-Bereiche hinzu. Beide Sätze müssen während des Übergangsfensters gleichzeitig auf die Zulassungsliste gesetzt werden.
Nach dem Enddatum des Übergangs: Setzen Sie die Zulassungsliste sowohl für die IP-Bereiche auf dieser Seite als auch für die einheitlichen IP-Bereiche auf die Zulassungsliste, bis ein nachfolgender Versionshinweis bestätigt, dass die Legacy-IP-Bereiche sicher entfernt werden können.
Terminologieaktualisierung – 31. Juli 2026
We renamed "outbound IP ranges" to IP ranges throughout this page. "Outbound" described UiPath's side of the connection, not yours — these ranges are what UiPath connects from, but from your firewall's perspective this traffic is inbound. Fully qualified domain names (FQDNs) remain the outbound side, from your perspective.
Hinweis zu veralteter Eigenschaft
The IP ranges on this page are being supplemented with a new unified set of IP ranges and will be gradually phased out starting September 16, 2026. This section summarizes the full timeline, scope, and required actions.
Was sich ändert
UiPath is consolidating all service-specific IP ranges into a single set of unified IP ranges, organized by global customer region rather than by individual service. The new unified ranges apply uniformly to all services within each region.
Betroffene Dienste: Test Cloud Portal, AI Trust Layer, Notification Service, Orchestrator, Test Manager, Apps, Automation Ops und Integration Service.
Not affected (no changes to their IP ranges): Document Understanding, Insights, IXP, and Automation Cloud Robots - Serverless.
Zeitleiste
| Meilenstein | Datum |
|---|---|
| Einheitliche IP-Bereiche veröffentlicht; Einstellung angekündigt; Das Fenster mit der zweifachen Zulassungsliste beginnt | 16. Juni 2026 |
| Das Fenster für die duale Zulassungsliste endet; Legacy-IP-Bereiche beginnen auslaufen | 16. September 2026 |
| Diese Seite wird nicht mehr aktualisiert | 16. September 2026 |
Was Sie tun müssen
- Add the unified IP ranges now. Visit the Configuring the firewall for Test Cloud page and add all ranges for your organization region and tenant region. Some UiPath service features inherit the organization's region rather than the tenant's region. If they differ, allowlist the IP ranges for both. For more information on organization-level and tenant-level services, see Global cloud regions. If your tenant or organization migrates to another region, update IP ranges accordingly.
- Vor dem Enddatum des Übergangs (siehe Zeitleiste): Lassen Sie die IP-Bereiche auf dieser Seite und die neuen einheitlichen IP-Bereiche gleichzeitig auf die Zulassungsliste setzen.
- Nach dem Enddatum des Übergangs: Setzen Sie die Zulassungsliste für beide Sätze von IP-Bereichen fort, bis ein späterer Versionshinweis bestätigt, dass die Legacy-IP-Bereiche sicher entfernt werden können.
- Allow applicable regional domains. For domain entries grouped by region, allow the domains listed for the region where your service is deployed. If your organization uses more than one region, allow the domains for each applicable region.
Test Cloud Portal
Erlauben Sie diese Domänen, die Test Cloud Portal verwendet:
Wenn Sie Azure-Buckets verwenden, dürfen sie sich nicht in der Region des Mandanten oder in der Failoverregion befinden.
Domänen
Allow the domains required for the sign-in method and portal functionality that your organization uses:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Mit Standardauthentifizierung anmelden | https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com | Auth0 login through social providers or with an email address and password is unavailable. Single sign-on remains available. |
| Mit Microsoft anmelden | https://aadcdn.msftauth.nethttps://account.uipath.comhttps://cloud.uipath.comhttps://login.live.comhttps://login.microsoftonline.comhttps://platform-cdn.uipath.com | Microsoft consumer-account and Microsoft Entra ID sign-in are unavailable, and Microsoft authentication pages may not render. |
| Mit Google anmelden | https://account.uipath.comhttps://cloud.uipath.comhttps://accounts.google.comhttps://google.comhttps://lh3.googleusercontent.comhttps://platform-cdn.uipath.comhttps://www.gstatic.com | Google sign-in may fail. |
| Mit LinkedIn anmelden | https://account.uipath.comhttps://cloud.uipath.comhttps://lnkd.demdex.nethttps://platform-cdn.uipath.comhttps://platform.linkedin.comhttps://static-exp1.licdn.comhttps://www.linkedin.com | LinkedIn sign-in may fail. |
| Mit Azure Active Directory anmelden (Azure AD) | https://aadcdn.msftauth.nethttps://cloud.uipath.comhttps://login.microsoftonline.com | Microsoft sign-in pages may not render, and single sign-on through Microsoft Entra ID is unavailable. |
| Use third-party packages with on-premises Studio and Robots | https://api.nuget.org | Optional. Third-party .NET packages from NuGet are unavailable. |
| Use UiPath Marketplace community packages | https://gallery.uipath.com | Optional. Community packages from UiPath Marketplace are unavailable. |
| Sign in for the first time or reset a password | uipath.eu.auth0.comaccount.uipath.com | Auth0 password setup and self-service password reset are unavailable. |
| Load portal fonts, styling, scripts, and images | https://use.typekit.nethttps://fonts.gstatic.comhttps://platform-cdn.uipath.comhttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.comhttps://fonts.googleapis.com/csshttps://p.typekit.nethttps://primer.typekit.net | Fonts, icons, images, or styling may not render correctly. |
| Sign in through Auth0 in the European Union | uipath.eu.auth0.com | Auth0 sign-in and password-management flows are unavailable. |
| Download Autopilot for Everyone | https://autopilot-prd.azureedge.net | Autopilot for Everyone cannot be downloaded from the AI Trust Layer admin section. |
IP ranges to enable a firewall for the customer-managed key
Required only when the Test Cloud Portal must connect to your Azure Key Vault for Customer-Managed Key (CMK) scenarios. These IP ranges represent the source IP ranges that your firewall must allow. For details, refer to the Enabling the firewall for the customer-managed key documentation.
The planned migration of Test Cloud Portal CMK IP ranges to new ranges — previously tracked as a separate transition (see the April 27, 2026 IP ranges completion announcement) — has been paused. This migration is now absorbed into the broader unified IP ranges transition. The IP ranges listed below remain active until the transition end date shown in the Timeline.
Allow these IP ranges through your firewall:
| Regionen | IP-Bereiche |
|---|---|
| Australien | |
| Kanada | |
| Community | |
| Europäische Union | |
| European Union — delayed update (GxP) | |
| Indien | |
| Japan | |
| Singapur | |
| Vereinigtes Königreich | |
| Vereinigte Staaten | |
| United States — delayed update (GxP) | |
IP ranges for notifications
You can configure Notification service systems to use SMTP servers from your own on-premises or cloud networks. If you want to provide additional security to your Notification service system, you can protect it with a firewall, and only allow Notification Service's static IP ranges through it.
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
Relais
Erlauben Sie diese Domänen, die der Relay-Client für den Aufbau einer Verbindung mit der Test Cloud verwendet:
| Zweck | Domänen | Protokoll | Port |
|---|---|---|---|
| Authentifizierung und Relay-Registrierung | cloud.uipath.com | https | 443 |
| Relay-Server – Region USA | us-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region EU | eu-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Kanada | ca-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Schweiz | ch-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Australien | au-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Singapur | sg-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Japan | jp-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Südkorea | kr-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – VAE-Region | ae-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
| Relay-Server – Region Vereinigtes Königreich | uk-relay.uipath.com | TCP (TLS-Passwort erforderlich) | 443 |
Action Center
Domänen
Allow the domains required for the Action Center functionality that your organization uses:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Authentifizieren | https://cloud.uipath.comhttps://account.uipath.com | Action Center or basic authentication is unavailable. |
| Open Action Center | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://www.youtube.comhttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. If YouTube is blocked, only the introductory video is unavailable. |
| View, assign, unassign, or delete an action | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. |
| Upload or download files from storage buckets | *.blob.core.windows.net | Files in form and app actions do not render, and Document Understanding tasks do not work. |
AI Center
Domänen
Allow the domains required for AI Center:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open AI Center and authenticate | https://cloud.uipath.com | AI Center is unavailable. |
| Load static assets | https://aifprodassets.azureedge.nethttps://i2.wp.com/cdn.auth0.comhttps://api.smartling.comhttps://s.gravatar.comhttps://js-agent.newrelic.comhttps://fonts.gstatic.comhttps://use.typekit.nethttps://fonts.googleapis.comhttps://d2c7xlmseob604.cloudfront.nethttps://du-prod-cdn.azureedge.net | AI Center does not load. |
| Complete OpenID configuration and receive service updates | https://cloud.uipath.comhttps://dc.services.visualstudio.comhttps://d2c7xlmseob604.cloudfront.nethttps://use.typekit.nethttps://fonts.googleapis.comhttps://aifstgassets.azureedge.nethttps://p.typekit.nethttps://fonts.gstatic.comhttps://api.smartling.comhttps://js-agent.newrelic.comhttps://i2.wp.com/cdn.auth0.comhttps://bam.eu01.nr-data.nethttps://du-prod-du-eus-signalr.service.signalr.netwss://du-prod-du-eus-signalr.service.signalr.net | AI Center authentication, configuration, or real-time updates may fail. |
| Access regional storage | Australien:https://aifproddataauetraining.blob.core.windows.netKanada: https://aifproddatacactraining.blob.core.windows.netEuropa: https://aifproddatawetraining.blob.core.windows.netJapan: https://aifproddatajaetraining.blob.core.windows.netSingapur: https://aifproddataseatraining.blob.core.windows.netUnited States: https://aifproddataeustraining.blob.core.windows.netEuropean Union — delayed update (GxP): https://aifgxpdatawetraining.blob.core.windows.net | AI Center cannot upload, train, deploy, or manage machine learning resources. |
| Send service telemetry | https://bam.eu01.nr-data.nethttps://eastus-6.in.applicationinsights.azure.com | No user-facing functionality is affected, but service telemetry used for support is unavailable. |
AI Computer Vision
In der folgenden Tabelle sind die Endpunktwerte und Serverstandorte aufgeführt, die von AI Computer Vision verwendet werden:
| Endpoint value | Server location | Impact if blocked |
|---|---|---|
https://cv.uipath.com | Nächste Position basierend auf der Anforderungs-IP | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-eu.uipath.com | Westeuropa | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-us.uipath.com | uns | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-delayed.uipath.com | Verzögerte Bereitstellung des Enterprise-Rings, lokal in den USA | Studio and Robot cannot use AI Computer Vision activities. |
AI Trust Layer – Einbringen Ihres eigenen LLM
IP-Bereiche
Allow the following IP ranges to establish communication between the Bring your own LLM functionality of AI Trust Layer, and your own system. The Bring your own LLM functionality depends on Integration Service connectors for communication. To use this capability and create connections successfully, you must also add the unified IP ranges for Integration Service to your allowlist.
Table 1. IP ranges for Bring your own LLM
| Region | IP-Bereiche |
|---|---|
| Australien | |
| Kanada | |
| Europa (Europäische Union) | |
| Europäische Union verzögert sich | |
| Community (Eeuropa) | |
| Indien | |
| Japan | |
| Singapur | 20.43.184.90 |
| Vereinigtes Königreich | |
| Vereinigte Staaten | |
| Vereinigte Staaten verzögert | |
Apps
Domänen
Allow the domains required for the Apps functionality that your organization uses:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Apps | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.host | Apps does not load. |
| Create or import apps, or add or delete processes | https://cloud.uipath.comhttps://uipath-apps-prd.azureedge.net | The affected app-authoring operations do not work. |
| Eine App exportieren, klonen, freigeben, löschen, bearbeiten oder veröffentlichen | https://cloud.uipath.com | The affected app-management operations do not work. |
| Ausführen oder Vorschau einer App | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.hosthttps://api.uipath.com | The app cannot run or render correctly. |
| Select processes or create a rule | https://uipath-apps-prd.azureedge.net | Process selection and rule creation do not work. |
| Bind a process | https://uipath-apps-prd.azureedge.nethttps://cloud.uipath.comhttps://dc.services.visualstudio.com | Process binding does not work. |
| Create or delete pages or history entries | https://cloud.uipath.com | Apps does not load, so page and history operations are unavailable. |
| Verbindung mit Apps herstellen | *.trafficmanager.netwss://*.uipath.systemswss://cloud.uipath.com | Apps does not load. Real-time collaboration updates require a page reload, and simultaneous editing can cause runtime errors. |
IP-Bereiche
The Apps service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| Region | IP-Bereiche |
|---|---|
| Europa | |
| Europa (Sekundär) | |
| Europa – Community | |
| Europa – Community (Sekundär) | |
| uns | |
| USA (Sekundär) | |
| Kanada | |
| Kanada (Sekundär) | |
| Singapur | |
| Japan | |
| Japan (Sekundär) | |
| Australien | |
| Australien (Sekundär) | |
| Indien | |
| Indien (Sekundär) | |
| Vereinigtes Königreich | |
| Vereinigtes Königreich (Sekundär) | |
| United States — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
Der Datenverkehr, der von diesen IP-Adressen abgeht, muss durch die DMZ der Firewall der Organisation und alle anderen zwischengeschalteten Firewalls genehmigt sein, einschließlich der Firewall auf dem/den Computer/n, wo die Orchestrator-Anwendung gehostet wird.
- Der zugehörige Port, auf dem die Orchestrator-Anwendung gehostet wird, muss durch die DMZ auf allen relevanten Firewalls offengelegt werden (siehe vorheriger Punkt).
- Ein Orchestrator-Benutzer, der für relevante Prozesse Berechtigungen zum Lesen und Ausführen hat, dessen Anmeldeinformationen von UiPath Apps verwendet werden, um mit dem Orchestrator zu interagieren.
- Wenn Sie die lokale Roboterprozessausführung über RobotJS verwenden, stellen Sie sicher, dass RobotJS mithilfe von RobotJS bereitgestellten Anweisungen ordnungsgemäß konfiguriert ist.
Best Practices
- Stellen Sie sicher, dass der lokal gehostete Orchestrator nur über einen sicheren HTTPS-Kanal zugänglich ist.
- Erstellen Sie im Orchestrator einen Benutzer, der über wenige Berechtigungen verfügt. Der Benutzer soll nur auf die gewünschten Prozesse/Ordner Zugriff haben und über Berechtigungen zum Lesen und Ausführen verfügen. Verwenden Sie das für die Integration.
CORS-Richtlinienanforderungen für Speicher-Buckets
Wenn Sie Speicher-Buckets aus einem lokalen oder hybriden Orchestrator verwenden, fügen Sie https://cloud.uipath.com zur acceptedRootURLs -Liste in der UiPath.Orchestrator.dll.config-Datei hinzu .
- Wenn Ihre Orchestrator-Instanz in Test Cloud gehostet wird, ist diese Konfiguration bereits eingerichtet.
- Konfigurieren Sie bei externen Buckets die zulässigen Ursprünge wie im Konfigurationshandbuch zu CORS und CSP beschrieben.
UiPath Apps lädt Dateien mithilfe der SAS-URL hoch und lädt sie herunter, die von Orchestrator bei der Interaktion mit Speicher-Buckets generiert wird, die in einer lokalen Umgebung gehostet werden. Endbenutzer müssen über die entsprechenden Berechtigungen verfügen, die über diese SAS-URL erteilt werden, um Upload- und Download-Vorgänge durchzuführen.
Die gesamte Zugriffssteuerung wird durch die zugrunde liegende Speicherkontokonfiguration definiert und erzwungen. UiPath verwaltet oder überschreibt diese Berechtigungen nicht.
Wenn bei Benutzern beim Hochladen oder Herunterladen von Dateien über UiPath Apps Fehler auftreten, sollte der Speicherbesitzer die SAS-Richtlinien oder Zugriffsbeschränkungen des Speicherkontos überprüfen und aktualisieren, um den erforderlichen Zugriffsgrad zu gewährleisten.
Inhaltstypen, die der Zulassungsliste hinzugefügt werden sollen
UiPath Apps verwendet die Inhaltstypen application/octet-stream und application/zip zum Herunterladen bestimmter DLL-Dateien, die zum Ausführen und Anzeigen der Vorschau erstellter Anwendungen erforderlich sind. Stellen Sie sicher, dass die folgenden Inhaltstypen in Ihren Netzwerkeinstellungen zulässig sind, um Unterbrechungen der App-Funktionalität zu vermeiden:
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
Wichtige Überlegungen
Apps werden mit der Blazor-Technologie entwickelt, die Assemblys direkt im Browser verarbeitet.Wenn Einschränkungen für die erforderlichen Inhaltstypen in Ihrem Netzwerk nicht aufgehoben werden können, funktionieren Apps möglicherweise nicht wie erwartet, da es keine alternativen Lösungen gibt, um diese Einschränkungen zu umgehen.
Apps in Studio Web als Alternative
Apps in Studio Web haben eine andere Architektur, bei der kein Herunterladen von DLL-Dateien erforderlich ist. Wenn Netzwerkeinschränkungen die Verwendung von eigenständigen Apps verhindern, sollten Sie die Einführung von Apps in Studio Web (RPA-Apps) in Betracht ziehen. Diese Architektur beseitigt die Abhängigkeit von eingeschränkten Inhaltstypen und gewährleistet eine reibungslosere Kompatibilität in eingeschränkten Netzwerkumgebungen.
Automation Cloud Robots – serverlos
IP-Bereiche
IP-Bereiche für Automation Cloud Robots – Serverless ermöglichen es Ihnen, ausgehenden Netzwerkdatenverkehr über dedizierte, statische IP-Adressbereiche weiterzuleiten, die von UiPath verwaltet werden. Dadurch können Sie externe Systeme auf die Zulassungsliste setzen oder sicher integrieren, die eingehende Verbindungen auf bekannte IPs beschränken.
Konfiguration
You can enable static IP ranges while creating the Serverless template and going to the Network Configuration page.
Verfügbarkeit
The IP ranges can sometimes change as a result of infrastructure deployments. To help keep you on top of any changes, we have compiled a list of up-to-date static IP ranges, in the following tables.
Community-Benutzer
| Region | CIDR | IP-Bereiche |
|---|---|---|
| Europa | | |
Enterprise-Benutzer
| Region | CIDR | IP-Bereiche |
|---|---|---|
| Australien | | |
| Vereinigte Staaten | | |
| Japan | | |
| Europa (Europäische Union) | | |
Automation Hub
Domänen
Allow the domains required for the Automation Hub functionality that your organization uses:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Automation Hub | https://cloud.uipath.comhttp://*.userpilot.iohttps://dc.services.visualstudio.comhttps://ah-prod-ts-blue-eu.uipath.comhttps://ah-prod-ts-blue-us.uipath.comhttps://ah-prod-ts-blue-ja.uipath.comhttps://ah-prod-ts-blue-au.uipath.comhttps://ah-prod-ts-blue-ca.uipath.comhttps://ah-prod-ts-blue-sea.uipath.comhttps://ah-prod-ts-blue-uk.uipath.comhttps://ah-prod-ts-blue-in.uipath.comhttps://ah-gxp-ts-blue-us.uipath.com | Automation Hub may not load. If Userpilot is blocked, first-time guidance is unavailable. If the telemetry endpoint is blocked, support telemetry is unavailable. |
| Use the Automation Hub Open API | https://automation-hub.uipath.comhttp://ah-gxp-openapi-us.uipath.com | Optional. Automation Hub Open API calls fail. |
Automation Ops
Domänen
Allow the domains required for the Automation Ops functionality that your organization uses:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Automation Ops | https://stdadmstgcdn.azureedge.nethttps://stdadmstgcdn.blob.core.windows.nethttps://nexus.ensighten.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.comhttps://use.typekit.nethttps://p.typekit.nethttps://content.usage.uipath.comhttps://data.usage.uipath.comhttps://*.service.signalr.netwss://*.service.signalr.nethttps://s.gravatar.comhttps://i2.wp.com | Automation Ops does not load or render correctly, and real-time updates are unavailable. |
| Use Source Control | https://github.comhttps://github.githubassets.comhttps://avatars.githubusercontent.comhttps://collector.github.comhttps://api.github.com | Source Control does not work. |
| Use Pipelines and send telemetry | https://app.vssps.visualstudio.comhttps://dc.services.visualstudio.com | Pipelines do not work. Blocking the telemetry endpoint also prevents support telemetry from being collected. |
IP-Bereiche
The table below lists all IP ranges used by Automation Ops.
| Region | IP-Bereiche |
|---|---|
| Australien | |
| Japan | |
| Vereinigte Staaten | |
| United States — delayed update (GxP) | |
| Europa | |
| European Union — delayed update (GxP) | |
| Kanada | |
| Singapur | |
| Indien | |
| Vereinigtes Königreich | |
IXP
Domänen
Allow the domains required for IXP:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open IXP and authenticate | https://cloud.uipath.com | IXP is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.com | Some interface elements may not render correctly. |
| Receive real-time portal updates | *.service.signalr.net | Notifications and other portal updates do not appear until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.comhttps://dc.services.visualstudio.com | Core functionality remains available, but business telemetry and diagnostic logs are unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | IXP remains available, but onboarding and interactive help are unavailable. |
| Send performance-monitoring data | https://o486811.ingest.sentry.io | No user-facing functionality is affected, but performance diagnostics are unavailable. |
Eingehende IP-Bereiche
Dieser Abschnitt gilt nur für Legacy-Re:infer-Kunden.
Fügen Sie die folgenden eingehenden IP-Bereiche zu Ihrer Zulassungsliste hinzu, um IXP zu verwenden und Verbindungen zu erstellen:
| Region | Eingehende IP-Bereiche |
|---|---|
| Europa | 34.91.100.206 |
| uns | |
| Japan | 34.84.144.176 |
| Australien | 35.189.46.91 |
| Kanada | 34.152.10.176 |
| Singapur | 35.240.179.214 |
IP-Bereiche
Lassen Sie die folgenden IP-Bereiche für IXP zu, um E-Mails von Ihrem Exchange zu synchronisieren. Weitere Informationen finden Sie unter Übersicht Exchange-Integration.
| Region | IP-Bereiche |
|---|---|
| Europa | 35.204.220.118 |
| uns | 34.71.173.219 |
| Japan | 34.84.107.92 |
| Australien | 34.87.223.173 |
| Kanada | 34.152.42.160 |
| Singapur | 34.143.128.81 |
Data Fabric
Domänen
Allow the domains required for Data Fabric:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Use Data Fabric | https://cloud.uipath.com | Data Fabric is unavailable. |
| Send service telemetry | *.visualstudio.com | No user-facing functionality is affected, but service telemetry is unavailable. |
Document Understanding
Domänen
Allow the domains required for the Document Understanding functionality that your organization uses:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Öffnen Sie Document Understanding. | https://*.uipath.com | Document Understanding does not load. |
| Send optional Azure telemetry | https://*.azure.com | Optional. Core functionality remains available, but telemetry used to investigate issues is unavailable. |
| Load the frontend | https://*.azureedge.net | Document Understanding does not load. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates do not appear until the page is refreshed. |
| Access legacy Document Manager storage | https://*.blob.core.windows.net | Document Manager does not work for projects created before 2023. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-product announcements and interactive guidance are unavailable. |
| Access public endpoints | See Public endpoints for the full list. | Information about predefined models and other public-endpoint functionality is unavailable. |
The legacy Document Manager storage domains apply only to projects created before 2023.
Fallback für den Cloudflare-IP-Bereich
Wenn Ihre Netzwerkeinrichtung keine DNS-basierte Zulassungsliste unterstützt, können Sie den Cloudflare IP-Bereich 104.16.0.0/13 als Fallback verwenden. Eine DNS-basierte Zulassungsliste wird empfohlen, da Cloudflare IP-Bereiche allgemein sind und sich ändern können.
Insights
Domänen
In der folgenden Tabelle sind die Domänen aufgeführt, die von Insights verwendet werden:
| Szenario | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Navigieren Sie zur Insights-Seite | https://cloud.uipath.comhttps://*.lookercdn.comhttps://uipath-insights-statics.azureedge.net/https://*.looker.uipath.com/ | Insights may not load, and some dashboards or visualizations may be blank. |
IP-Bereiche
Mit IP-Bereichen können Sie eine Liste von IPs für die Funktionen Protokollexport und Datenexport auf die Zulassungsliste setzen und müssen Ihr Netzwerk nicht mehr für alle externen IPs öffnen. Wenn die Blob-Speicherregionen der jeweiligen Insights-Dienstregion entsprechen, können Sie keine öffentlichen IPs verwenden.
| Region des Insights-Diensts | Blob-Speicherregion | Funktion | Statische IP-Bereiche |
|---|---|---|---|
| Europa |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Vereinigte Staaten von Amerika |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Australien |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Japan |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Kanada |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Singapur |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Indien |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| Vereinigtes Königreich |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| United States — delayed update (GxP) |
| Export von Protokollen | 134.33.240.104 |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | | ||
| European Union — delayed update (GxP) |
| Export von Protokollen | |
| Datenexport | | ||
| Looker SFTP-Benachrichtigungen | |
Einschränkungen
Für den Protokollexport unterstützt Google Storage keine IP-Beschränkungen für eingehende Verbindungen.
Aufgrund einer Einschränkung auf Microsoft-Seite für den Protokollexport können Sie keine IP-Beschränkung für eingehende Verbindungen einrichten, wenn sich Ihr Azure-Blobspeicherkonto und die Insights-Infrastruktur in Azure in derselben Region befinden. Aus diesem Grund können Sie die folgenden Regionen für ein Blob-Speicherkonto basierend auf der Region des Insights-Diensts nicht verwenden:
- Insights USA: Nordeuropa, USA Ost
- Insights Europa: Nordeuropa, Westeuropa (für Community-Lizenzierung)
- Insights GB: Nordeuropa, GB Süd
- Insights Kanada: Nordeuropa, Zentralkanada
- Insights Singapur: Nordeuropa, Südostasien
- Insights Indien: Nordeuropa, Zentralindien
- Insights Australien: Nordeuropa, Australien (Osten).
- Insights Japan: Nordeuropa, Japan (Osten).
- Insights — European Union — delayed update (GxP): North Europe, East US
- Insights — United States — delayed update (GxP): East US
Weitere Informationen zu dieser Einschränkung finden Sie auf der Seite Einschränkungen für IP-Netzwerkregeln in der Dokumentation zu Microsoft Azure Blob Storage.
Integration Service
IP-Bereiche
Add the following IP ranges to your allow list to use Integration Service and create connections, as described in the following table.
| Region | IP-Bereiche | Umgebung |
|---|---|---|
| Australien | | Produktion |
| Kanada | | Produktion |
| Europa | | Produktion |
| Japan | | Produktion |
| Indien | | Produktion |
| Singapur | | Produktion |
| Vereinigtes Königreich | | Produktion |
| Vereinigte Staaten | | Produktion |
| United States — delayed update (GxP) | | Produktion |
| Community | | Produktion |
IP-Adressen, die mit einem Sternchen () gekennzeichnet sind, werden neu integrierten Azure-Regionen zugewiesen. Diese IPs ersetzen die vorhandenen regionalen IPs nach Abschluss des geplanten Mandantenmigration. Weitere Informationen finden Sie in den Versionshinweisen zu Integration Service.
Orchestrator
Domänen
Allow the domains required for Orchestrator and Robot functionality:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Orchestrator | https://cloud.uipath.comhttps://orch-cdn.uipath.comhttps://account.uipath.com | The Orchestrator frontend does not load. |
| Connect Cloud Robots - VM to UiPath services | https://cloud.uipath.com | The Robot and agent on the provisioned VM cannot communicate with UiPath services. |
| Download Studio and Robot installers for Cloud Robots - VM | https://download.uipath.com | Optional if you install and manage the Robot yourself. Otherwise, Studio and Robot installers cannot be downloaded. |
| Access Orchestrator storage | *.blob.core.windows.netBei Verwendung von Amazon S3-Buckets: *.s3.amazonaws.com | Package upload and download, suspended jobs, video recording, storage buckets, and other storage-backed functionality do not work. Provisioned Cloud Robots - VM also cannot connect to UiPath infrastructure. |
| Download packages and libraries | https://pkgs.dev.azure.com | Libraries and packages from the host feed cannot be downloaded. |
| Use Azure SignalR | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates and live streaming fail, attended jobs cannot be stopped remotely, and some Robot or activity events can be delayed by up to 30 seconds. |
| Update Studio and Robot automatically | https://download.uipath.com | Studio and Robot cannot update automatically. |
| Use Live Streaming and Remote Control | *.uipath.comhttps://*.uipath.comwss://*.uipath.com | Live Streaming and Remote Control do not work. |
IP-Bereiche
We recommend allowing these IP ranges, which send traffic from Orchestrator towards your resources. For details, refer to Orchestrator IP ranges.
Community-Benutzer
| Region | CIDR | IP-Bereiche |
|---|---|---|
| Europa (Europäische Union) | | |
Enterprise-Benutzer
| Region | CIDR | IP-Bereiche |
|---|---|---|
| Australien | | |
| Kanada | | |
| Vereinigte Staaten | | |
| Japan | | |
| Europa (Europäische Union) | | |
| Singapur | | |
| Vereinigtes Königreich | | |
| Indien | | |
Delayed update (GxP) organizations
| Region | CIDR | IP-Bereiche |
|---|---|---|
| Europa (Europäische Union) | | |
| Vereinigte Staaten | | |
MCP-Server
The remote MCP Servers service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| Region | IP-Bereiche |
|---|---|
| Europa | |
| Europa (Sekundär) | |
| Europa – Community | |
| Europa – Community (Sekundär) | |
| uns | |
| USA (Sekundär) | |
| Kanada | |
| Kanada (Sekundär) | |
| Singapur | |
| Japan | |
| Japan (Sekundär) | |
| Australien | |
| Australien (Sekundär) | |
| Indien | |
| Indien (Sekundär) | |
| Vereinigtes Königreich | |
| Vereinigtes Königreich (Sekundär) | |
| European Union — delayed update (GxP) | |
| European Union — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
| United States — delayed update (GxP), secondary | |
Process Mining
Domänen
Allow the domains required for Process Mining:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Process Mining | https://cloud.uipath.com | Process Mining is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.comhttps://content.usage.uipath.comhttps://s.gravatar.comhttps://i1.wp.com | Process Mining may not load or render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | The interface can display outdated information until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.com | Optional. Core functionality remains available, but diagnostic information used for support is unavailable. |
| Upload data to Process Mining | *.blob.core.windows.net | Process Mining cannot ingest data or create process apps. |
Solutions (Lösungen)
Domänen
Allow the domains required for Solutions Management:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Solutions Management | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://fonts.gstatic.comhttps://dc.services.visualstudio.comapi.smartling.comuse.typekit.netp.typekit.nets.gravatar.comi2.wp.comhttps://platform-cdn.uipath.comhttps://sol-cdn.uipath.comhttps://solutions.uipath.com | Solutions Management or required interface assets may be unavailable. |
| Upload or download solution packages | *.blob.core.windows.net | Solution packages cannot be uploaded or downloaded. |
| Receive live deployment updates | https://*.service.signalr.netwss://*.service.signalr.net | Live status updates, including deployment progress, do not appear until the page is refreshed. |
Studio Web
Domänen
Allow the domains required for Studio Web:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Receive real-time collaboration updates | wss://*.service.signalr.nethttps://*.service.signalr.netwss://*.trafficmanager.net | Live updates for project imports, shared projects, and other notifications are unavailable. |
| Open Studio Web | https://*.uipath.com | Studio Web is unavailable. |
| Send in-app feedback | https://studio-feedback.azure-api.net | In-app feedback cannot be submitted. |
| Load static assets | https://platform-cdn.uipath.comhttps://content.usage.uipath.comhttps://fonts.gstatic.comhttps://d2c7xlmseob604.cloudfront.nethttps://fonts.googleapis.comhttps://*.typekit.nethttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.com | Fonts, icons, images, or other static assets may not render correctly. |
| Send product telemetry | https://data.usage.uipath.com | Optional. Core functionality remains available, but product telemetry is unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-app guidance is unavailable. |
| Send third-party telemetry | https://dc.services.visualstudio.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load translated interface content | https://api.smartling.com | Translated interface content may be unavailable. |
Task Mining
Domänen
Allow the domains required for Task Mining desktop components:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Task Mining | https://cloud.uipath.com | Task Mining is unavailable. |
| Use the web portal | *.blob.core.windows.net | The Task Mining web portal does not function correctly. |
| Receive desktop-component notifications | *.service.signalr.net | The desktop component may not receive real-time updates. |
| Use Pendo in-app guidance | https://content.usage.uipath.com | In-app guidance is unavailable. |
| Send Azure Application Insights telemetry | dc.services.visualstudio.comdc.applicationinsights.azure.comdc.applicationinsights.microsoft.com*.in.applicationinsights.azure.comlive.applicationinsights.azure.comrt.applicationinsights.microsoft.comrt.services.visualstudio.com{region}.livediagnostics.monitor.azure.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load user avatars | i2.wp.com/cdn.auth0.com/avatars | User avatars do not render. |
Task Mining uses HTTPS and WSS over port 443. Configure transparent proxies to permit both protocols.
Test Manager
This section lists the domains used by Test Manager and the IP ranges that you should consider allowing if you want to use various Test Manager capabilities.
Domänen
Allow the domains required for Test Manager:
| Scenario or functionality | Domänen, die zugelassen werden sollen | Impact if blocked |
|---|---|---|
| Open Test Manager | https://cloud.uipath.com | Test Manager is unavailable or its interface does not render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Some interface updates do not appear until the page is refreshed. |
SAP Heatmap and CIA RFC IP ranges
Allow the following IP ranges to establish communication between UiPath Test Manager and your SAP system via an RFC connection.
The following table shows the available IP ranges for each region.
| Region | IP-Bereiche |
|---|---|
| Australien | |
| Kanada | |
| Europa (Europäische Union) | |
| Indien | |
| United States — delayed update (GxP) | |
| Japan | |
| Singapur | |
| Vereinigtes Königreich | |
| Vereinigte Staaten | |
SAP Heatmap and CIA Web Service IP ranges
Allow the following static IP ranges to enable the communication between UiPath Test Manager and your SAP system, via a web service connection.
Allow these IP ranges through your firewall:
| Regionen | IP-Bereiche |
|---|---|
| Australien | |
| Kanada | |
| Community | |
| Europäische Union | |
| European Union — delayed update (GxP) | |
| Indien | |
| Japan | |
| Singapur | |
| Vereinigtes Königreich | |
| Vereinigte Staaten | |
| United States — delayed update (GxP) | |
IP ranges for connectors
If you enhance your system's security with a firewall, consider allowing only Test Manager IP ranges for using out-of-the-box connectors.
The following IP ranges apply to all supported regions, including: Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP).
Allow these IP ranges through your firewall:
| Regionen | IP-Bereiche |
|---|---|
| Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP) | |
- Hinweis zu veralteter Eigenschaft
- Was sich ändert
- Zeitleiste
- Was Sie tun müssen
- Test Cloud Portal
- Domänen
- IP ranges to enable a firewall for the customer-managed key
- IP ranges for notifications
- Relais
- Action Center
- Domänen
- AI Center
- Domänen
- AI Computer Vision
- AI Trust Layer – Einbringen Ihres eigenen LLM
- IP-Bereiche
- Apps
- Domänen
- IP-Bereiche
- Inhaltstypen, die der Zulassungsliste hinzugefügt werden sollen
- Automation Cloud Robots – serverlos
- IP-Bereiche
- Automation Hub
- Domänen
- Automation Ops
- Domänen
- IP-Bereiche
- IXP
- Domänen
- Eingehende IP-Bereiche
- IP-Bereiche
- Data Fabric
- Domänen
- Document Understanding
- Domänen
- Fallback für den Cloudflare-IP-Bereich
- Insights
- Domänen
- IP-Bereiche
- Integration Service
- IP-Bereiche
- Orchestrator
- Domänen
- IP-Bereiche
- MCP-Server
- Process Mining
- Domänen
- Solutions (Lösungen)
- Domänen
- Studio Web
- Domänen
- Task Mining
- Domänen
- Test Manager
- Domänen
- SAP Heatmap and CIA RFC IP ranges
- SAP Heatmap and CIA Web Service IP ranges
- IP ranges for connectors