- Démarrage
- Sécurité et conformité des données
- Sécurité et conformité des données
- Encryption
- Certificats
- Sécurité fonctionnelle
- Configuration du pare-feu pour Test Cloud
- Héritage - Configuration du pare-feu pour Test Cloud
- Configurer le pare-feu pour Test Cloud pour le secteur public
- Configuration du pare-feu pour Test Cloud dédié
- Déploiement de fonctionnalités
- Stratégie de haute disponibilité et de Disaster Recovery
- Organisations
- Authentification et sécurité
- Licences
- À propos des licences
- Tarification unifiée : infrastructure du plan de licence
- Activation de votre licence Enterprise
- Migrer de Test Suite vers Test Cloud
- Migration de licence
- Attribuer des licences aux locataires
- Attribuer des licences utilisateur
- Révocation des licences utilisateur
- Surveillance de l’attribution des licences
- Surallocation de licences
- Notifications d'attribution de licence
- Gestion des licences utilisateur
- Locataires et services
- Comptes et rôles
- AI Trust Layer
- À propos de AI Trust Layer
- Vérification du résumé de l'utilisation
- Affichage des journaux d'audit
- Gestion des politiques AI Trust Layer
- Masquage PII
- Gestion d’Autopilot for Everyone
- Configuration des LLM
- Restriction des appels LLM à vos propres modèles
- Configuration de OpenTelemetry
- Gouvernance des données contextuelles pour les fonctionnalités GenAI
- Applications externes
- Notifications
- Journalisation
- Exporter des données
- Test dans votre organisation
- Résolution des problèmes
- Migrer vers Test Cloud
Legacy IP ranges for Test Cloud services, provided for reference during the transition to the unified IP range configuration.
Pour des informations générales sur la configuration réseau et le pare-feu, reportez-vous à Configuration du pare-feu
Avis d’obsolescence — action requise
The IP ranges listed on this page are being deprecated. As of June 16, 2026, new unified IP ranges have been published and must be added to your allowlist alongside these ranges. Starting September 16, 2026, the IP ranges on this page will be gradually phased out. For specific dates, see the Timeline in the Deprecation notice section below.
Avant la date de fin de la transition: conservez ces plages d'adresses IP dans la configuration de votre pare-feu et ajoutez les nouvelles plages d'adresses IP unifiées. Les deux ensembles doivent être ajoutés à la liste d'autorisation simultanée pendant la fenêtre de transition.
Après la date de fin de la transition: continuez à autoriser la liste d'autorisation à la fois des plages d'adresses IP sur cette page et des plages d'adresses IP unifiées jusqu'à ce qu'une note de publication ultérieure confirme que les plages d'adresses IP héritées peuvent être supprimées en toute sécurité.
Mise à jour terminologique — 31 juillet 2026
We renamed "outbound IP ranges" to IP ranges throughout this page. "Outbound" described UiPath's side of the connection, not yours — these ranges are what UiPath connects from, but from your firewall's perspective this traffic is inbound. Fully qualified domain names (FQDNs) remain the outbound side, from your perspective.
Avis d'obsolescence
The IP ranges on this page are being supplemented with a new unified set of IP ranges and will be gradually phased out starting September 16, 2026. This section summarizes the full timeline, scope, and required actions.
Ce qui change
UiPath is consolidating all service-specific IP ranges into a single set of unified IP ranges, organized by global customer region rather than by individual service. The new unified ranges apply uniformly to all services within each region.
Services affectés : Test Cloud Portal, AI Trust Layer, Notification Service, Orchestrator, Test Manager, Apps, Automation Ops et Integration Service.
Not affected (no changes to their IP ranges): Document Understanding, Insights, IXP, and Automation Cloud Robots - Serverless.
Chronologie
| Étape (Milestone) | Date |
|---|---|
| Plages d’adresses IP unifiées publiées; obsolescence annoncée; la fenêtre des listes d’autorisations doubles commence | 16 juin 2026 |
| La fenêtre de la double liste d’autorisation se termine; Les plages d'adresses IP héritées commencent à être supprimées | 16 septembre 2026 |
| Cette page n’est plus mise à jour | 16 septembre 2026 |
Ce que vous devez faire
- Add the unified IP ranges now. Visit the Configuring the firewall for Test Cloud page and add all ranges for your organization region and tenant region. Some UiPath service features inherit the organization's region rather than the tenant's region. If they differ, allowlist the IP ranges for both. For more information on organization-level and tenant-level services, see Global cloud regions. If your tenant or organization migrates to another region, update IP ranges accordingly.
- Avant la date de fin de la transition (voir Chronologie): conservez les plages d'adresses IP sur cette page et les nouvelles plages d'adresses IP unifiées sont toutes deux ajoutées à la liste d'autorisation simultanée.
- Après la date de fin de la transition: continuez à autoriser la liste d'autorisation des deux ensembles de plages d'adresses IP jusqu'à ce qu'une note de publication ultérieure confirme que les plages d'adresses IP héritées peuvent être supprimées en toute sécurité.
- Allow applicable regional domains. For domain entries grouped by region, allow the domains listed for the region where your service is deployed. If your organization uses more than one region, allow the domains for each applicable region.
Portail Test Cloud
Autorisez ces domaines à être utilisés par Test Cloud Portal :
Si vous utilisez des compartiments Azure, ils ne doivent pas être situés dans la région du locataire ou dans la région de basculement.
Domaines
Allow the domains required for the sign-in method and portal functionality that your organization uses:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Connexion avec une authentification de base | https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com | Auth0 login through social providers or with an email address and password is unavailable. Single sign-on remains available. |
| Connexion avec Microsoft | https://aadcdn.msftauth.nethttps://account.uipath.comhttps://cloud.uipath.comhttps://login.live.comhttps://login.microsoftonline.comhttps://platform-cdn.uipath.com | Microsoft consumer-account and Microsoft Entra ID sign-in are unavailable, and Microsoft authentication pages may not render. |
| Connexion avec Google | https://account.uipath.comhttps://cloud.uipath.comhttps://accounts.google.comhttps://google.comhttps://lh3.googleusercontent.comhttps://platform-cdn.uipath.comhttps://www.gstatic.com | Google sign-in may fail. |
| Connexion avec LinkedIn | https://account.uipath.comhttps://cloud.uipath.comhttps://lnkd.demdex.nethttps://platform-cdn.uipath.comhttps://platform.linkedin.comhttps://static-exp1.licdn.comhttps://www.linkedin.com | LinkedIn sign-in may fail. |
| Connexion avec Azure Active Directory (Azure AD) | https://aadcdn.msftauth.nethttps://cloud.uipath.comhttps://login.microsoftonline.com | Microsoft sign-in pages may not render, and single sign-on through Microsoft Entra ID is unavailable. |
| Use third-party packages with on-premises Studio and Robots | https://api.nuget.org | Optional. Third-party .NET packages from NuGet are unavailable. |
| Use UiPath Marketplace community packages | https://gallery.uipath.com | Optional. Community packages from UiPath Marketplace are unavailable. |
| Sign in for the first time or reset a password | uipath.eu.auth0.comaccount.uipath.com | Auth0 password setup and self-service password reset are unavailable. |
| Load portal fonts, styling, scripts, and images | https://use.typekit.nethttps://fonts.gstatic.comhttps://platform-cdn.uipath.comhttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.comhttps://fonts.googleapis.com/csshttps://p.typekit.nethttps://primer.typekit.net | Fonts, icons, images, or styling may not render correctly. |
| Sign in through Auth0 in the European Union | uipath.eu.auth0.com | Auth0 sign-in and password-management flows are unavailable. |
| Download Autopilot for Everyone | https://autopilot-prd.azureedge.net | Autopilot for Everyone cannot be downloaded from the AI Trust Layer admin section. |
IP ranges to enable a firewall for the customer-managed key
Required only when the Test Cloud Portal must connect to your Azure Key Vault for Customer-Managed Key (CMK) scenarios. These IP ranges represent the source IP ranges that your firewall must allow. For details, refer to the Enabling the firewall for the customer-managed key documentation.
The planned migration of Test Cloud Portal CMK IP ranges to new ranges — previously tracked as a separate transition (see the April 27, 2026 IP ranges completion announcement) — has been paused. This migration is now absorbed into the broader unified IP ranges transition. The IP ranges listed below remain active until the transition end date shown in the Timeline.
Allow these IP ranges through your firewall:
| Régions | Plages d'adresses IP |
|---|---|
| Australie | |
| Canada | |
| Communauté | |
| Union européenne | |
| European Union — delayed update (GxP) | |
| Inde | |
| Japon | |
| Singapour | |
| Royaume-Uni | |
| États-Unis | |
| United States — delayed update (GxP) | |
IP ranges for notifications
You can configure Notification service systems to use SMTP servers from your own on-premises or cloud networks. If you want to provide additional security to your Notification service system, you can protect it with a firewall, and only allow Notification Service's static IP ranges through it.
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
Relais
Autorisez ces domaines utilisés par le client Relay pour établir la connectivité à Test Cloud :
| Objectif | Domaines | Protocole | Port |
|---|---|---|---|
| Authentification et enregistrement du Relay | cloud.uipath.com | https | 443 |
| Serveur de relais - Région États-Unis | us-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région UE | eu-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région du Canada | ca-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région Suisse | ch-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région d’Australie | au-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région de Singapour | sg-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région du Japon | jp-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région de Corée du Sud | kr-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région des Émirats arabes unis | ae-relay.uipath.com | TCP (passage TLS requis) | 443 |
| Serveur de relais - Région Royaume-Uni | uk-relay.uipath.com | TCP (passage TLS requis) | 443 |
Action Center
Domaines
Allow the domains required for the Action Center functionality that your organization uses:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Authentifier | https://cloud.uipath.comhttps://account.uipath.com | Action Center or basic authentication is unavailable. |
| Open Action Center | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://www.youtube.comhttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. If YouTube is blocked, only the introductory video is unavailable. |
| View, assign, unassign, or delete an action | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. |
| Upload or download files from storage buckets | *.blob.core.windows.net | Files in form and app actions do not render, and Document Understanding tasks do not work. |
AI Center
Domaines
Allow the domains required for AI Center:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open AI Center and authenticate | https://cloud.uipath.com | AI Center is unavailable. |
| Load static assets | https://aifprodassets.azureedge.nethttps://i2.wp.com/cdn.auth0.comhttps://api.smartling.comhttps://s.gravatar.comhttps://js-agent.newrelic.comhttps://fonts.gstatic.comhttps://use.typekit.nethttps://fonts.googleapis.comhttps://d2c7xlmseob604.cloudfront.nethttps://du-prod-cdn.azureedge.net | AI Center does not load. |
| Complete OpenID configuration and receive service updates | https://cloud.uipath.comhttps://dc.services.visualstudio.comhttps://d2c7xlmseob604.cloudfront.nethttps://use.typekit.nethttps://fonts.googleapis.comhttps://aifstgassets.azureedge.nethttps://p.typekit.nethttps://fonts.gstatic.comhttps://api.smartling.comhttps://js-agent.newrelic.comhttps://i2.wp.com/cdn.auth0.comhttps://bam.eu01.nr-data.nethttps://du-prod-du-eus-signalr.service.signalr.netwss://du-prod-du-eus-signalr.service.signalr.net | AI Center authentication, configuration, or real-time updates may fail. |
| Access regional storage | Australie :https://aifproddataauetraining.blob.core.windows.netCanada : https://aifproddatacactraining.blob.core.windows.netEurope : https://aifproddatawetraining.blob.core.windows.netJapon : https://aifproddatajaetraining.blob.core.windows.netSingapour : https://aifproddataseatraining.blob.core.windows.netUnited States: https://aifproddataeustraining.blob.core.windows.netEuropean Union — delayed update (GxP): https://aifgxpdatawetraining.blob.core.windows.net | AI Center cannot upload, train, deploy, or manage machine learning resources. |
| Send service telemetry | https://bam.eu01.nr-data.nethttps://eastus-6.in.applicationinsights.azure.com | No user-facing functionality is affected, but service telemetry used for support is unavailable. |
AI Computer Vision
Le tableau suivant répertorie les valeurs de point de terminaison et les emplacements de serveur utilisés par AI Computer Vision :
| Endpoint value | Server location | Impact if blocked |
|---|---|---|
https://cv.uipath.com | Géolocalisation la plus proche en fonction de l'adresse IP demandée | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-eu.uipath.com | Europe de l'ouest | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-us.uipath.com | us | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-delayed.uipath.com | Déploiement différé du réseau d'entreprise, situé aux États-Unis | Studio and Robot cannot use AI Computer Vision activities. |
AI Trust Layer : apportez votre propre LLM
Plages d'adresses IP
Allow the following IP ranges to establish communication between the Bring your own LLM functionality of AI Trust Layer, and your own system. The Bring your own LLM functionality depends on Integration Service connectors for communication. To use this capability and create connections successfully, you must also add the unified IP ranges for Integration Service to your allowlist.
Table 1. IP ranges for Bring your own LLM
| Region | Plages d'adresses IP |
|---|---|
| Australie | |
| Canada | |
| Europe (Union européenne) | |
| L'Union européenne a été retardée | |
| Communauté (Europe) | |
| Inde | |
| Japon | |
| Singapour | 20.43.184.90 |
| Royaume-Uni | |
| États-Unis | |
| États-Unis Retardé | |
Apps
Domaines
Allow the domains required for the Apps functionality that your organization uses:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Apps | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.host | Apps does not load. |
| Create or import apps, or add or delete processes | https://cloud.uipath.comhttps://uipath-apps-prd.azureedge.net | The affected app-authoring operations do not work. |
| Exporter, cloner, partager, supprimer, modifier ou publier une application | https://cloud.uipath.com | The affected app-management operations do not work. |
| Exécuter ou prévisualiser une application | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.hosthttps://api.uipath.com | The app cannot run or render correctly. |
| Select processes or create a rule | https://uipath-apps-prd.azureedge.net | Process selection and rule creation do not work. |
| Bind a process | https://uipath-apps-prd.azureedge.nethttps://cloud.uipath.comhttps://dc.services.visualstudio.com | Process binding does not work. |
| Create or delete pages or history entries | https://cloud.uipath.com | Apps does not load, so page and history operations are unavailable. |
| Se connecter à Apps | *.trafficmanager.netwss://*.uipath.systemswss://cloud.uipath.com | Apps does not load. Real-time collaboration updates require a page reload, and simultaneous editing can cause runtime errors. |
Plages d'adresses IP
The Apps service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| Region | Plages d'adresses IP |
|---|---|
| Europe | |
| Europe (Secondaire) | |
| Europe - Communauté | |
| Europe - Communauté (Secondaire) | |
| us | |
| US (Secondaire) | |
| Canada | |
| Canada (Secondaire) | |
| Singapour | |
| Japon | |
| Japon (Secondaire) | |
| Australie | |
| Australie (Secondaire) | |
| Inde | |
| Inde (Secondaire) | |
| Royaume-Uni | |
| Royaume-Uni (Secondaire) | |
| United States — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
Le trafic provenant de ces adresses IP doit être autorisé via le pare-feu DMZ de l'organisation et tout autre pare-feu intermédiaire, y compris le pare-feu sur le ou les ordinateurs sur lesquels l'application Orchestrator est hébergée.
- Le port associé sur lequel l'application Orchestrator est hébergée doit être exposé via le pare-feu DMZ sur tous les pare-feux concernés (voir le point précédent).
- Un utilisateur d'Orchestrator qui dispose d'un accès en lecture et en exécution aux processus pertinents dont les informations d'identification seront utilisées à partir des applications UiPath pour communiquer avec Orchestrator.
- Si vous utilisez l'exécution de processus de robot local via Robotjs, assurez-vous que Robotjs est correctement configuré à l'aide des instructions fournies sur RobotJS.
Meilleures pratiques
- Assurez-vous que l'instance d'Orchestrator hébergée sur site n'est accessible que via un canal https sécurisé.
- Créez un utilisateur à faible privilège dans Orchestrator qui ne dispose d'un accès en lecture et en exécution qu'aux processus/dossiers souhaités et utilisez-le dans le cadre de l'intégration.
Exigences de la politique CORS pour les compartiments de stockage
Lorsque vous utilisez des compartiments de stockage à partir d’une instance Orchestrator sur site ou hybride, ajoutez https://cloud.uipath.com à la liste acceptedRootURLs dans le fichier UiPath.Orchestrator.dll.config.
- Si votre instance d'Orchestrator est hébergée dans Test Cloud, cette configuration est déjà en place.
- Pour les compartiments externes, configurez les origines autorisées comme décrit dans le guide de configuration de CORS et de CSP. »
Les applications UiPath chargent et téléchargent des fichiers à l'aide de l'URL SAS générée par Orchestrator lors de l'interaction avec des compartiments de stockage hébergés dans un environnement local. Les utilisateurs finaux doivent disposer des autorisations appropriées accordées via cette URL SAS pour effectuer à la fois des opérations de chargement et de téléchargement.
L'ensemble du contrôle d'accès est défini et appliqué par la configuration du compte de stockage sous-jacent. UiPath ne gère ni ne remplace ces autorisations.
Si les utilisateurs rencontrent des erreurs lors du chargement ou du téléchargement de fichiers via les Apps UiPath, les politiques SAS ou les restrictions d'accès du compte de stockage doivent être examinées et mises à jour par le propriétaire du stockage pour garantir le niveau d'accès requis.
Types de contenu à ajouter à la liste d’autorisation
UiPath Apps utilise les types de contenu application/octet-stream et application/zip pour télécharger des fichiers DLL spécifiques nécessaires pour exécuter et prévisualiser les applications créées. Il est important de vous assurer que les types de contenu suivants sont autorisés dans les paramètres de votre réseau afin d'éviter les interruptions de la fonctionnalité de l'application :
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
Considérations clés
Les applications sont développées à l'aide de la technologie Blazor, qui traite les assemblages directement dans le navigateur. Si les restrictions pour les types de contenu requis ne peuvent pas être levées dans votre réseau, les applications peuvent ne pas fonctionner comme prévu, car il n'existe aucune solution alternative pour contourner ces limitations.
Applications dans Studio Web comme alternative
Les applications de Studio Web sont conçues avec une architecture différente, qui ne nécessite pas de télécharger des fichiers DLL. Si les restrictions du réseau empêchent l'utilisation d'applications autonomes, envisagez d'adopter Apps dans Studio Web (Apps RPA). Cette architecture élimine la dépendance à des types de contenu restreints, garantissant une compatibilité plus fluide dans les environnements réseau restreints.
Automation Cloud Robots - Serverless
Plages d'adresses IP
Les plages d'adresses IP pour Automation Cloud Robots - Serverless vous permettent d’acheminer le trafic réseau sortant via une plage d’adresses IP statiques dédiées gérées par UiPath. Cela vous permet d’autoriser la liste d’autorisation ou de vous intégrer en toute sécurité à des systèmes externes qui restreignent les connexions entrantes aux adresses IP connues.
Configuration
You can enable static IP ranges while creating the Serverless template and going to the Network Configuration page.
Disponibilité
The IP ranges can sometimes change as a result of infrastructure deployments. To help keep you on top of any changes, we have compiled a list of up-to-date static IP ranges, in the following tables.
Utilisateurs Community
| Region | CIDR | Plages d'adresses IP |
|---|---|---|
| Europe | | |
Utilisateurs Enterprise
| Region | CIDR | Plages d'adresses IP |
|---|---|---|
| Australie | | |
| États-Unis | | |
| Japon | | |
| Europe (Union européenne) | | |
Automation Hub
Domaines
Allow the domains required for the Automation Hub functionality that your organization uses:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Automation Hub | https://cloud.uipath.comhttp://*.userpilot.iohttps://dc.services.visualstudio.comhttps://ah-prod-ts-blue-eu.uipath.comhttps://ah-prod-ts-blue-us.uipath.comhttps://ah-prod-ts-blue-ja.uipath.comhttps://ah-prod-ts-blue-au.uipath.comhttps://ah-prod-ts-blue-ca.uipath.comhttps://ah-prod-ts-blue-sea.uipath.comhttps://ah-prod-ts-blue-uk.uipath.comhttps://ah-prod-ts-blue-in.uipath.comhttps://ah-gxp-ts-blue-us.uipath.com | Automation Hub may not load. If Userpilot is blocked, first-time guidance is unavailable. If the telemetry endpoint is blocked, support telemetry is unavailable. |
| Use the Automation Hub Open API | https://automation-hub.uipath.comhttp://ah-gxp-openapi-us.uipath.com | Optional. Automation Hub Open API calls fail. |
Automation Ops
Domaines
Allow the domains required for the Automation Ops functionality that your organization uses:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Automation Ops | https://stdadmstgcdn.azureedge.nethttps://stdadmstgcdn.blob.core.windows.nethttps://nexus.ensighten.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.comhttps://use.typekit.nethttps://p.typekit.nethttps://content.usage.uipath.comhttps://data.usage.uipath.comhttps://*.service.signalr.netwss://*.service.signalr.nethttps://s.gravatar.comhttps://i2.wp.com | Automation Ops does not load or render correctly, and real-time updates are unavailable. |
| Use Source Control | https://github.comhttps://github.githubassets.comhttps://avatars.githubusercontent.comhttps://collector.github.comhttps://api.github.com | Source Control does not work. |
| Use Pipelines and send telemetry | https://app.vssps.visualstudio.comhttps://dc.services.visualstudio.com | Pipelines do not work. Blocking the telemetry endpoint also prevents support telemetry from being collected. |
Plages d'adresses IP
The table below lists all IP ranges used by Automation Ops.
| Region | Plages d'adresses IP |
|---|---|
| Australie | |
| Japon | |
| États-Unis | |
| United States — delayed update (GxP) | |
| Europe | |
| European Union — delayed update (GxP) | |
| Canada | |
| Singapour | |
| Inde | |
| Royaume-Uni | |
IXP
Domaines
Allow the domains required for IXP:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open IXP and authenticate | https://cloud.uipath.com | IXP is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.com | Some interface elements may not render correctly. |
| Receive real-time portal updates | *.service.signalr.net | Notifications and other portal updates do not appear until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.comhttps://dc.services.visualstudio.com | Core functionality remains available, but business telemetry and diagnostic logs are unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | IXP remains available, but onboarding and interactive help are unavailable. |
| Send performance-monitoring data | https://o486811.ingest.sentry.io | No user-facing functionality is affected, but performance diagnostics are unavailable. |
Plages d’adresses IP entrantes
Cette section s’applique uniquement aux clients Re:infer existants.
Ajoutez les plages d’adresses IP entrantes suivantes à votre liste d’autorisation pour utiliser IXP et créer des connexions :
| Region | Plages d’adresses IP entrantes |
|---|---|
| Europe | 34.91.100.206 |
| us | |
| Japon | 34.84.144.176 |
| Australie | 35.189.46.91 |
| Canada | 34.152.10.176 |
| Singapour | 35.240.179.214 |
Plages d'adresses IP
Autorisez les plages d'adresses IP suivantes pour IXP afin de synchroniser les e-mails de votre système Exchange. Pour en savoir plus, consultez la section Aperçu de l’intégration d’échange.
| Region | Plages d'adresses IP |
|---|---|
| Europe | 35.204.220.118 |
| us | 34.71.173.219 |
| Japon | 34.84.107.92 |
| Australie | 34.87.223.173 |
| Canada | 34.152.42.160 |
| Singapour | 34.143.128.81 |
Data Fabric
Domaines
Allow the domains required for Data Fabric:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Use Data Fabric | https://cloud.uipath.com | Data Fabric is unavailable. |
| Send service telemetry | *.visualstudio.com | No user-facing functionality is affected, but service telemetry is unavailable. |
Document Understanding
Domaines
Allow the domains required for the Document Understanding functionality that your organization uses:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Ouvrir Document Understanding | https://*.uipath.com | Document Understanding does not load. |
| Send optional Azure telemetry | https://*.azure.com | Optional. Core functionality remains available, but telemetry used to investigate issues is unavailable. |
| Load the frontend | https://*.azureedge.net | Document Understanding does not load. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates do not appear until the page is refreshed. |
| Access legacy Document Manager storage | https://*.blob.core.windows.net | Document Manager does not work for projects created before 2023. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-product announcements and interactive guidance are unavailable. |
| Access public endpoints | See Public endpoints for the full list. | Information about predefined models and other public-endpoint functionality is unavailable. |
The legacy Document Manager storage domains apply only to projects created before 2023.
Cloudflare - Plage d’adresses IP
Si votre matériel réseau ne prend pas en charge la liste d'autorisation basée sur DNS, vous pouvez utiliser la plage d'adresses IP Cloudflare 104.16.0.0/13 comme solution de secours. La liste d’autorisation basée sur le DNS est recommandée, car les plages d’adresses IP de Cloudflare sont larges et peuvent changer.
Insights
Domaines
Le tableau suivant répertorie les domaines utilisés par Insights :
| Scénario | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Accéder à la page Insights | https://cloud.uipath.comhttps://*.lookercdn.comhttps://uipath-insights-statics.azureedge.net/https://*.looker.uipath.com/ | Insights may not load, and some dashboards or visualizations may be blank. |
Plages d'adresses IP
Les plages d'adresses IP vous permettent d'ajouter une liste d'adresses IP pour les fonctionnalités d'exportation de journaux et d'exportation de données à la liste d'autorisation et de ne pas ouvrir votre réseau à toutes les adresses IP externes. Si les régions de stockage d'objets blob correspondent à la région de service Insights respective, vous ne pouvez pas utiliser d'adresses IP publiques.
| Région du service Insights | Région de stockage d'objets blob | Fonctionnalité | Plages d'adresses IP statiques |
|---|---|---|---|
| Europe |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| États-Unis d’Amérique |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| Australie |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| Japon |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| Canada |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| Singapour |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| Inde |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| Royaume-Uni |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| United States — delayed update (GxP) |
| Exportation de journaux | 134.33.240.104 |
| Exporter des données | | ||
| Notifications SFTP de Looker | | ||
| European Union — delayed update (GxP) |
| Exportation de journaux | |
| Exporter des données | | ||
| Notifications SFTP de Looker | |
Limitations
Pour l'exportation de journaux, Google Storage ne prend pas en charge la restriction de l'IP entrante.
En raison d'une limitation côté Microsoft pour l'exportation de journaux, vous ne pouvez pas configurer de restriction d'adresse IP entrante lorsque votre compte de stockage d'objets blob Azure et l'infrastructure Insights se trouvent dans la même région dans Azure. Pour cette raison, vous ne pouvez pas utiliser les régions suivantes pour le compte de stockage d'objets blob en fonction de la région de service Insights :
- Insights États-Unis : Europe du Nord, Est des États-Unis
- Insights Europe : Europe du Nord, Europe de l'Ouest (pour les licences Community License)
- Insights Royaume-Uni : Europe du Nord, Sud du Royaume-Uni
- Insights Canada : Europe du Nord, Centre du Canada
- Insights Singapour : Europe du Nord, Asie du Sud-Est
- Insights India : Europe du Nord, Inde centrale
- Insights Australie : Europe du Nord, Australie de l'Est
- Insights Japon : Europe du Nord, Japon de l'Est
- Insights — European Union — delayed update (GxP): North Europe, East US
- Insights — United States — delayed update (GxP): East US
Pour plus d’informations sur cette limitation, vérifiez la page Restrictions des règles réseau IP dans la documentation de Microsoft Azure Blob Storage.
Integration Service
Plages d'adresses IP
Add the following IP ranges to your allow list to use Integration Service and create connections, as described in the following table.
| Region | Plages d'adresses IP | Environnement (Environment) |
|---|---|---|
| Australie | | Production |
| Canada | | Production |
| Europe | | Production |
| Japon | | Production |
| Inde | | Production |
| Singapour | | Production |
| Royaume-Uni | | Production |
| États-Unis | | Production |
| United States — delayed update (GxP) | | Production |
| Communauté | | Production |
Les adresses IP marquées d'un astérisque () sont désignées pour les régions Azure nouvellement intégrées. Ces IP remplaceront les IP régionales existantes à la fin du processus de migration planifié du locataire. Pour plus de détails, reportez-vous aux notes de version Integration Service.
Orchestrator
Domaines
Allow the domains required for Orchestrator and Robot functionality:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Orchestrator | https://cloud.uipath.comhttps://orch-cdn.uipath.comhttps://account.uipath.com | The Orchestrator frontend does not load. |
| Connect Cloud Robots - VM to UiPath services | https://cloud.uipath.com | The Robot and agent on the provisioned VM cannot communicate with UiPath services. |
| Download Studio and Robot installers for Cloud Robots - VM | https://download.uipath.com | Optional if you install and manage the Robot yourself. Otherwise, Studio and Robot installers cannot be downloaded. |
| Access Orchestrator storage | *.blob.core.windows.netSi vous utilisez des compartiments Amazon S3 : *.s3.amazonaws.com | Package upload and download, suspended jobs, video recording, storage buckets, and other storage-backed functionality do not work. Provisioned Cloud Robots - VM also cannot connect to UiPath infrastructure. |
| Download packages and libraries | https://pkgs.dev.azure.com | Libraries and packages from the host feed cannot be downloaded. |
| Use Azure SignalR | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates and live streaming fail, attended jobs cannot be stopped remotely, and some Robot or activity events can be delayed by up to 30 seconds. |
| Update Studio and Robot automatically | https://download.uipath.com | Studio and Robot cannot update automatically. |
| Use Live Streaming and Remote Control | *.uipath.comhttps://*.uipath.comwss://*.uipath.com | Live Streaming and Remote Control do not work. |
Plages d'adresses IP
We recommend allowing these IP ranges, which send traffic from Orchestrator towards your resources. For details, refer to Orchestrator IP ranges.
Utilisateurs de la communauté
| Region | CIDR | Plages d'adresses IP |
|---|---|---|
| Europe (Union européenne) | | |
Utilisateurs Enterprise
| Region | CIDR | Plages d'adresses IP |
|---|---|---|
| Australie | | |
| Canada | | |
| États-Unis | | |
| Japon | | |
| Europe (Union européenne) | | |
| Singapour | | |
| Royaume-Uni | | |
| Inde | | |
Delayed update (GxP) organizations
| Region | CIDR | Plages d'adresses IP |
|---|---|---|
| Europe (Union européenne) | | |
| États-Unis | | |
Serveurs MCP
The remote MCP Servers service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| Region | Plages d'adresses IP |
|---|---|
| Europe | |
| Europe (Secondaire) | |
| Europe - Communauté | |
| Europe - Communauté (Secondaire) | |
| us | |
| US (Secondaire) | |
| Canada | |
| Canada (Secondaire) | |
| Singapour | |
| Japon | |
| Japon (Secondaire) | |
| Australie | |
| Australie (Secondaire) | |
| Inde | |
| Inde (Secondaire) | |
| Royaume-Uni | |
| Royaume-Uni (Secondaire) | |
| European Union — delayed update (GxP) | |
| European Union — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
| United States — delayed update (GxP), secondary | |
Process Mining
Domaines
Allow the domains required for Process Mining:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Process Mining | https://cloud.uipath.com | Process Mining is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.comhttps://content.usage.uipath.comhttps://s.gravatar.comhttps://i1.wp.com | Process Mining may not load or render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | The interface can display outdated information until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.com | Optional. Core functionality remains available, but diagnostic information used for support is unavailable. |
| Upload data to Process Mining | *.blob.core.windows.net | Process Mining cannot ingest data or create process apps. |
Solutions
Domaines
Allow the domains required for Solutions Management:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Solutions Management | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://fonts.gstatic.comhttps://dc.services.visualstudio.comapi.smartling.comuse.typekit.netp.typekit.nets.gravatar.comi2.wp.comhttps://platform-cdn.uipath.comhttps://sol-cdn.uipath.comhttps://solutions.uipath.com | Solutions Management or required interface assets may be unavailable. |
| Upload or download solution packages | *.blob.core.windows.net | Solution packages cannot be uploaded or downloaded. |
| Receive live deployment updates | https://*.service.signalr.netwss://*.service.signalr.net | Live status updates, including deployment progress, do not appear until the page is refreshed. |
Studio Web
Domaines
Allow the domains required for Studio Web:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Receive real-time collaboration updates | wss://*.service.signalr.nethttps://*.service.signalr.netwss://*.trafficmanager.net | Live updates for project imports, shared projects, and other notifications are unavailable. |
| Open Studio Web | https://*.uipath.com | Studio Web is unavailable. |
| Send in-app feedback | https://studio-feedback.azure-api.net | In-app feedback cannot be submitted. |
| Load static assets | https://platform-cdn.uipath.comhttps://content.usage.uipath.comhttps://fonts.gstatic.comhttps://d2c7xlmseob604.cloudfront.nethttps://fonts.googleapis.comhttps://*.typekit.nethttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.com | Fonts, icons, images, or other static assets may not render correctly. |
| Send product telemetry | https://data.usage.uipath.com | Optional. Core functionality remains available, but product telemetry is unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-app guidance is unavailable. |
| Send third-party telemetry | https://dc.services.visualstudio.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load translated interface content | https://api.smartling.com | Translated interface content may be unavailable. |
Task Mining
Domaines
Allow the domains required for Task Mining desktop components:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Task Mining | https://cloud.uipath.com | Task Mining is unavailable. |
| Use the web portal | *.blob.core.windows.net | The Task Mining web portal does not function correctly. |
| Receive desktop-component notifications | *.service.signalr.net | The desktop component may not receive real-time updates. |
| Use Pendo in-app guidance | https://content.usage.uipath.com | In-app guidance is unavailable. |
| Send Azure Application Insights telemetry | dc.services.visualstudio.comdc.applicationinsights.azure.comdc.applicationinsights.microsoft.com*.in.applicationinsights.azure.comlive.applicationinsights.azure.comrt.applicationinsights.microsoft.comrt.services.visualstudio.com{region}.livediagnostics.monitor.azure.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load user avatars | i2.wp.com/cdn.auth0.com/avatars | User avatars do not render. |
Task Mining uses HTTPS and WSS over port 443. Configure transparent proxies to permit both protocols.
Test Manager
This section lists the domains used by Test Manager and the IP ranges that you should consider allowing if you want to use various Test Manager capabilities.
Domaines
Allow the domains required for Test Manager:
| Scenario or functionality | Domaines à autoriser | Impact if blocked |
|---|---|---|
| Open Test Manager | https://cloud.uipath.com | Test Manager is unavailable or its interface does not render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Some interface updates do not appear until the page is refreshed. |
SAP Heatmap and CIA RFC IP ranges
Allow the following IP ranges to establish communication between UiPath Test Manager and your SAP system via an RFC connection.
The following table shows the available IP ranges for each region.
| Region | Plages d'adresses IP |
|---|---|
| Australie | |
| Canada | |
| Europe (Union européenne) | |
| Inde | |
| United States — delayed update (GxP) | |
| Japon | |
| Singapour | |
| Royaume-Uni | |
| États-Unis | |
SAP Heatmap and CIA Web Service IP ranges
Allow the following static IP ranges to enable the communication between UiPath Test Manager and your SAP system, via a web service connection.
Allow these IP ranges through your firewall:
| Régions | Plages d'adresses IP |
|---|---|
| Australie | |
| Canada | |
| Communauté | |
| Union européenne | |
| European Union — delayed update (GxP) | |
| Inde | |
| Japon | |
| Singapour | |
| Royaume-Uni | |
| États-Unis | |
| United States — delayed update (GxP) | |
IP ranges for connectors
If you enhance your system's security with a firewall, consider allowing only Test Manager IP ranges for using out-of-the-box connectors.
The following IP ranges apply to all supported regions, including: Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP).
Allow these IP ranges through your firewall:
| Régions | Plages d'adresses IP |
|---|---|
| Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP) | |
- Avis d'obsolescence
- Ce qui change
- Chronologie
- Ce que vous devez faire
- Portail Test Cloud
- Domaines
- IP ranges to enable a firewall for the customer-managed key
- IP ranges for notifications
- Relais
- Action Center
- Domaines
- AI Center
- Domaines
- AI Computer Vision
- AI Trust Layer : apportez votre propre LLM
- Plages d'adresses IP
- Apps
- Domaines
- Plages d'adresses IP
- Types de contenu à ajouter à la liste d’autorisation
- Automation Cloud Robots - Serverless
- Plages d'adresses IP
- Automation Hub
- Domaines
- Automation Ops
- Domaines
- Plages d'adresses IP
- IXP
- Domaines
- Plages d’adresses IP entrantes
- Plages d'adresses IP
- Data Fabric
- Domaines
- Document Understanding
- Domaines
- Cloudflare - Plage d’adresses IP
- Insights
- Domaines
- Plages d'adresses IP
- Integration Service
- Plages d'adresses IP
- Orchestrator
- Domaines
- Plages d'adresses IP
- Serveurs MCP
- Process Mining
- Domaines
- Solutions
- Domaines
- Studio Web
- Domaines
- Task Mining
- Domaines
- Test Manager
- Domaines
- SAP Heatmap and CIA RFC IP ranges
- SAP Heatmap and CIA Web Service IP ranges
- IP ranges for connectors