- スタート アップ ガイド
- データのセキュリティとコンプライアンス
- 組織
- 認証とセキュリティ
- ライセンス
- テナントとサービス
- アカウントとロール
- AI Trust Layer
- 外部アプリケーション
- 通知
- ログ
- データ エクスポート
- 組織でのテスト
- トラブルシューティング
- Test Cloud に移行する
Legacy IP ranges for Test Cloud services, provided for reference during the transition to the unified IP range configuration.
一般的なネットワーク構成とファイアウォールに関する情報については、「ファイアウォールを設定する」をご覧ください。
非推奨化のお知らせ — 必要な対応
The IP ranges listed on this page are being deprecated. As of June 16, 2026, new unified IP ranges have been published and must be added to your allowlist alongside these ranges. Starting September 16, 2026, the IP ranges on this page will be gradually phased out. For specific dates, see the Timeline in the Deprecation notice section below.
移行終了日より前: これらの IP 範囲をファイアウォール設定に保持 し、 新しい Unified IP 範囲を追加します。移行期間中に両方のセットを同時に許可リストに登録する必要があります。
移行終了日以降: レガシ IP 範囲を安全に削除できることが今後のリリース ノートで確認されるまで、このページの IP 範囲と Unified IP 範囲の両方を許可リストに登録し続けます。
用語の更新 — 2026 年 7 月 31 日
We renamed "outbound IP ranges" to IP ranges throughout this page. "Outbound" described UiPath's side of the connection, not yours — these ranges are what UiPath connects from, but from your firewall's perspective this traffic is inbound. Fully qualified domain names (FQDNs) remain the outbound side, from your perspective.
非推奨化のお知らせ
The IP ranges on this page are being supplemented with a new unified set of IP ranges and will be gradually phased out starting September 16, 2026. This section summarizes the full timeline, scope, and required actions.
変更点
UiPath is consolidating all service-specific IP ranges into a single set of unified IP ranges, organized by global customer region rather than by individual service. The new unified ranges apply uniformly to all services within each region.
影響を受けるサービス: Test Cloud ポータル、AI Trust Layer、通知サービス、Orchestrator、Test Manager、Apps、Automation Ops、Integration Service。
Not affected (no changes to their IP ranges): Document Understanding, Insights, IXP, and Automation Cloud Robots - Serverless.
タイムライン
| マイルストーン | 日付 |
|---|---|
| Unified IP 範囲が公開されています。非推奨化の発表。デュアル許可リスト ウィンドウの開始 | 2026 年 6 月 16 日 |
| デュアル許可リスト ウィンドウが終了します。レガシーIP範囲の段階的廃止を開始 | 2026 年 9 月 16 日 |
| このページは更新されなくなりました | 2026 年 9 月 16 日 |
以下を実行する必要があります
- Add the unified IP ranges now. Visit the Configuring the firewall for Test Cloud page and add all ranges for your organization region and tenant region. Some UiPath service features inherit the organization's region rather than the tenant's region. If they differ, allowlist the IP ranges for both. For more information on organization-level and tenant-level services, see Global cloud regions. If your tenant or organization migrates to another region, update IP ranges accordingly.
- 移行終了日より前 ( 「タイムライン」を参照): このページの IP 範囲と新しい Unified IP 範囲 の両方 を同時に許可リストに登録したままにします。
- 移行終了日以降: 次のリリース ノートでレガシ IP 範囲を安全に削除できることが確認されるまで、両方の IP 範囲セットを許可リストに登録し続けます。
- Allow applicable regional domains. For domain entries grouped by region, allow the domains listed for the region where your service is deployed. If your organization uses more than one region, allow the domains for each applicable region.
Test Cloud ポータル
Test Cloud ポータルで使用される以下のドメインを許可します。
Azure バケットを使用する場合は、テナントのリージョンまたはフェールオーバー リージョンに配置してはなりません。
ドメイン
Allow the domains required for the sign-in method and portal functionality that your organization uses:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| 基本認証によるサインイン | https://account.uipath.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.com | Auth0 login through social providers or with an email address and password is unavailable. Single sign-on remains available. |
| Microsoft でのサインイン | https://aadcdn.msftauth.nethttps://account.uipath.comhttps://cloud.uipath.comhttps://login.live.comhttps://login.microsoftonline.comhttps://platform-cdn.uipath.com | Microsoft consumer-account and Microsoft Entra ID sign-in are unavailable, and Microsoft authentication pages may not render. |
| Google でのサインイン | https://account.uipath.comhttps://cloud.uipath.comhttps://accounts.google.comhttps://google.comhttps://lh3.googleusercontent.comhttps://platform-cdn.uipath.comhttps://www.gstatic.com | Google sign-in may fail. |
| LinkedIn でのサインイン | https://account.uipath.comhttps://cloud.uipath.comhttps://lnkd.demdex.nethttps://platform-cdn.uipath.comhttps://platform.linkedin.comhttps://static-exp1.licdn.comhttps://www.linkedin.com | LinkedIn sign-in may fail. |
| Azure Active Directory (Azure AD) でのサインイン | https://aadcdn.msftauth.nethttps://cloud.uipath.comhttps://login.microsoftonline.com | Microsoft sign-in pages may not render, and single sign-on through Microsoft Entra ID is unavailable. |
| Use third-party packages with on-premises Studio and Robots | https://api.nuget.org | Optional. Third-party .NET packages from NuGet are unavailable. |
| Use UiPath Marketplace community packages | https://gallery.uipath.com | Optional. Community packages from UiPath Marketplace are unavailable. |
| Sign in for the first time or reset a password | uipath.eu.auth0.comaccount.uipath.com | Auth0 password setup and self-service password reset are unavailable. |
| Load portal fonts, styling, scripts, and images | https://use.typekit.nethttps://fonts.gstatic.comhttps://platform-cdn.uipath.comhttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.comhttps://fonts.googleapis.com/csshttps://p.typekit.nethttps://primer.typekit.net | Fonts, icons, images, or styling may not render correctly. |
| Sign in through Auth0 in the European Union | uipath.eu.auth0.com | Auth0 sign-in and password-management flows are unavailable. |
| Download Autopilot for Everyone | https://autopilot-prd.azureedge.net | Autopilot for Everyone cannot be downloaded from the AI Trust Layer admin section. |
IP ranges to enable a firewall for the customer-managed key
Required only when the Test Cloud Portal must connect to your Azure Key Vault for Customer-Managed Key (CMK) scenarios. These IP ranges represent the source IP ranges that your firewall must allow. For details, refer to the Enabling the firewall for the customer-managed key documentation.
The planned migration of Test Cloud Portal CMK IP ranges to new ranges — previously tracked as a separate transition (see the April 27, 2026 IP ranges completion announcement) — has been paused. This migration is now absorbed into the broader unified IP ranges transition. The IP ranges listed below remain active until the transition end date shown in the Timeline.
Allow these IP ranges through your firewall:
| リージョン | IP 範囲 |
|---|---|
| オーストラリア | |
| カナダ | |
| Community | |
| 欧州連合 | |
| European Union — delayed update (GxP) | |
| インド | |
| 日本 | |
| シンガポール | |
| 英国 | |
| 米国 | |
| United States — delayed update (GxP) | |
IP ranges for notifications
You can configure Notification service systems to use SMTP servers from your own on-premises or cloud networks. If you want to provide additional security to your Notification service system, you can protect it with a firewall, and only allow Notification Service's static IP ranges through it.
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
20.213.69.140/30
20.92.42.116/30
20.220.159.8/30
20.104.134.160/30
20.239.121.152/30
20.232.224.12/30
20.78.114.120/30
104.215.9.124/30
20.166.153.132/30
20.198.150.140/30
20.23.210.168/30
20.66.65.144/30
149.72.70.144
Relay
Relay クライアントによって使用される以下のドメインが Test Cloud への接続を確立できるようにします。
| 目的 | ドメイン | プロトコル | ポート |
|---|---|---|---|
| 認証とリレー登録 | cloud.uipath.com | https | 443 |
| リレー サーバー - 米国リージョン | us-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| リレー サーバー - EU リージョン | eu-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| Relay Server - カナダ リージョン | ca-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| リレー サーバー - スイス リージョン | ch-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| Relay Server - オーストラリア リージョン | au-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| リレー サーバー - シンガポール リージョン | sg-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| 中継サーバー - 日本リージョン | jp-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| リレー サーバー - 韓国リージョン | kr-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| リレー サーバー - アラブ首長国連邦 リージョン | ae-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
| リレー サーバー - 英国リージョン | uk-relay.uipath.com | TCP (TLS パススルーが必要) | 443 |
Action Center
ドメイン
Allow the domains required for the Action Center functionality that your organization uses:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| 認証 | https://cloud.uipath.comhttps://account.uipath.com | Action Center or basic authentication is unavailable. |
| Open Action Center | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://www.youtube.comhttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. If YouTube is blocked, only the introductory video is unavailable. |
| View, assign, unassign, or delete an action | https://cloud.uipath.comhttps://uipath-acc-prod.azureedge.nethttps://platform-cdn.uipath.comhttps://fonts.gstatic.com*.googleapis.com | Action Center or required frontend assets may be unavailable. |
| Upload or download files from storage buckets | *.blob.core.windows.net | Files in form and app actions do not render, and Document Understanding tasks do not work. |
AI Center
ドメイン
Allow the domains required for AI Center:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open AI Center and authenticate | https://cloud.uipath.com | AI Center is unavailable. |
| Load static assets | https://aifprodassets.azureedge.nethttps://i2.wp.com/cdn.auth0.comhttps://api.smartling.comhttps://s.gravatar.comhttps://js-agent.newrelic.comhttps://fonts.gstatic.comhttps://use.typekit.nethttps://fonts.googleapis.comhttps://d2c7xlmseob604.cloudfront.nethttps://du-prod-cdn.azureedge.net | AI Center does not load. |
| Complete OpenID configuration and receive service updates | https://cloud.uipath.comhttps://dc.services.visualstudio.comhttps://d2c7xlmseob604.cloudfront.nethttps://use.typekit.nethttps://fonts.googleapis.comhttps://aifstgassets.azureedge.nethttps://p.typekit.nethttps://fonts.gstatic.comhttps://api.smartling.comhttps://js-agent.newrelic.comhttps://i2.wp.com/cdn.auth0.comhttps://bam.eu01.nr-data.nethttps://du-prod-du-eus-signalr.service.signalr.netwss://du-prod-du-eus-signalr.service.signalr.net | AI Center authentication, configuration, or real-time updates may fail. |
| Access regional storage | オーストラリアhttps://aifproddataauetraining.blob.core.windows.netカナダ https://aifproddatacactraining.blob.core.windows.netヨーロッパ https://aifproddatawetraining.blob.core.windows.net日本 https://aifproddatajaetraining.blob.core.windows.netシンガポール https://aifproddataseatraining.blob.core.windows.netUnited States: https://aifproddataeustraining.blob.core.windows.netEuropean Union — delayed update (GxP): https://aifgxpdatawetraining.blob.core.windows.net | AI Center cannot upload, train, deploy, or manage machine learning resources. |
| Send service telemetry | https://bam.eu01.nr-data.nethttps://eastus-6.in.applicationinsights.azure.com | No user-facing functionality is affected, but service telemetry used for support is unavailable. |
AI Computer Vision
次の表に、AI Computer Vision で使用されるエンドポイントの値とサーバーの場所を示します。
| Endpoint value | Server location | Impact if blocked |
|---|---|---|
https://cv.uipath.com | リクエスト IP に基づく最も近い地理的位置 | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-eu.uipath.com | westeurope | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-us.uipath.com | 米国 | Studio and Robot cannot use AI Computer Vision activities. |
https://cv-delayed.uipath.com | Delayed Enterprise Ring Deployment (遅延エンタープライズ リングのデプロイ) (米国) | Studio and Robot cannot use AI Computer Vision activities. |
AI Trust Layer – 独自の LLM を使用する
IP 範囲
Allow the following IP ranges to establish communication between the Bring your own LLM functionality of AI Trust Layer, and your own system. The Bring your own LLM functionality depends on Integration Service connectors for communication. To use this capability and create connections successfully, you must also add the unified IP ranges for Integration Service to your allowlist.
Table 1. IP ranges for Bring your own LLM
| リージョン | IP 範囲 |
|---|---|
| オーストラリア | |
| カナダ | |
| 欧州 (欧州連合) | |
| 欧州連合 (遅延) | |
| Community (ヨーロッパ) | |
| インド | |
| 日本 | |
| シンガポール | 20.43.184.90 |
| 英国 | |
| 米国 | |
| 米国 (遅延) | |
Apps (アプリ)
ドメイン
Allow the domains required for the Apps functionality that your organization uses:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Apps | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.host | Apps does not load. |
| Create or import apps, or add or delete processes | https://cloud.uipath.comhttps://uipath-apps-prd.azureedge.net | The affected app-authoring operations do not work. |
| アプリのエクスポート、複製、共有、削除、編集またはパブリッシュ | https://cloud.uipath.com | The affected app-management operations do not work. |
| アプリの実行 またはプレビュー | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://cdnjs.cloudflare.comhttps://uipath-apps-prd.azureedge.nethttps://fonts.gstatic.comhttps://dc.services.visualstudio.comhttps://<orgname>.uipath.hosthttps://api.uipath.com | The app cannot run or render correctly. |
| Select processes or create a rule | https://uipath-apps-prd.azureedge.net | Process selection and rule creation do not work. |
| Bind a process | https://uipath-apps-prd.azureedge.nethttps://cloud.uipath.comhttps://dc.services.visualstudio.com | Process binding does not work. |
| Create or delete pages or history entries | https://cloud.uipath.com | Apps does not load, so page and history operations are unavailable. |
| アプリへの接続 | *.trafficmanager.netwss://*.uipath.systemswss://cloud.uipath.com | Apps does not load. Real-time collaboration updates require a page reload, and simultaneous editing can cause runtime errors. |
IP 範囲
The Apps service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| リージョン | IP 範囲 |
|---|---|
| 欧州 | |
| 欧州 (セカンダリ) | |
| 欧州 - Community | |
| 欧州 - Community (セカンダリ) | |
| 米国 | |
| 米国 (セカンダリ) | |
| カナダ | |
| カナダ (セカンダリ) | |
| シンガポール | |
| 日本 | |
| 日本 (セカンダリ) | |
| オーストラリア | |
| オーストラリア (セカンダリ) | |
| インド | |
| インド (セカンダリ) | |
| 英国 | |
| 英国 (セカンダリ) | |
| United States — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
この IP からのトラフィックは、組織の DMZ ファイアウォール、および Orchestrator アプリケーションがホストされているコンピューター上のファイアウォールを含むその他の中間ファイアウォールで許可される必要があります。
- Orchestrator アプリケーションがホストされている関連ポートは、関連するすべてのファイアウォールで DMZ を経由して公開される必要があります (上述の説明をご覧ください)。
- 関連プロセスの読み取り・実行アクセス権を持つ Orchestrator ユーザーの資格情報が UiPath Apps から取得され、Orchestrator との対話に使用されます。
- Robotjs を用いてローカルのロボットでプロセスを実行する場合、Robotjs が「RobotJS」で示された手順に従って適切に設定されていることを確認してください。
ベスト プラクティス
- オンプレミスでホストされる Orchestrator には、セキュリティで保護された https チャネルを通じてのみアクセスできるようにします。
- 目的のプロセス/フォルダーのみに対して読み取りおよび実行アクセス権だけを持つ、特権の低いユーザーを Orchestrator に作成し、そのユーザーを連携に使用します。
ストレージ バケットの CORS ポリシーの要件
オンプレミスまたはハイブリッドの Orchestrator のストレージ バケットを使用する場合は、UiPath.Orchestrator.dll.config ファイルの acceptedRootURLs リストに https://cloud.uipath.com を追加します。
- Orchestrator インスタンスが Test Cloud でホストされている場合、この構成は既に実施されています。
- 外部バケットの場合は、 CORS と CSP の設定 ガイドの説明に従って、許可されたオリジンを設定します。
UiPath Apps は、オンプレミス環境でホストされているストレージ バケットを操作するときに、Orchestrator によって生成された SAS URL を使用してファイルをアップロードおよびダウンロードします。エンド ユーザーがアップロード操作とダウンロード操作の両方を実行するには、その SAS URL を介して適切な権限が付与されている必要があります。
すべてのアクセス制御は、基になるストレージ アカウント構成によって定義および適用されます。UiPath では、これらの権限の管理や上書きは行われません。
UiPath Apps を使用してファイルをアップロードまたはダウンロードしているときにエラーが発生した場合は、ストレージ アカウントの SAS ポリシーまたはアクセス制限 をストレージ所有者が確認および更新して、必要なレベルのアクセス権を確保する必要があります。
許可リストに追加するコンテンツの種類
UiPath Apps では、作成したアプリケーションの実行とプレビューに必要な特定の DLL ファイルをダウンロードするために、application/octet-stream と application/zip のコンテンツの種類を利用します。アプリの機能が中断されないように、ネットワーク設定内で次のコンテンツの種類が許可されていることを確認することが重要です。
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
application/zip
application/octet-stream
application/json
text/html
application/javascript
text/css
font/woff2
image/vnd.microsoft.icon
image/svg+xml
image/bmp
image/jpeg
image/png
image/gif
主な考慮事項
Apps は、アセンブリをブラウザーで直接処理する Blazor テクノロジを使用して開発されています。必要なコンテンツの種類に対する制限をネットワーク内で解除できない場合、これらの制限を回避する代替ソリューションはないため、Apps が期待どおりに動作しない可能性があります。
代替手段としての Studio Web の Apps
Studio Web のアプリは異なるアーキテクチャで設計されているため、DLL ファイルをダウンロードする必要はありません。ネットワークの制限によりスタンドアロンの Apps を使用できない場合は、Apps を Studio Web に導入 (RPA Apps) することを検討してください。このアーキテクチャにより、制限されたコンテンツの種類への依存がなくなり、制限されたネットワーク環境でのよりスムーズな相互運用性が確保されます。
Automation Cloud ロボット - サーバーレス
IP 範囲
Automation Cloud ロボット - サーバーレスの IP 範囲を使用すると、UiPath が管理する専用の静的 IP アドレス範囲を通じて送信ネットワーク トラフィックをルーティングできます。これにより、受信コネクションを既知の IP からのみに制限している外部システムを許可リストに登録したり、セキュリティで保護された連携が可能になります。
構成
You can enable static IP ranges while creating the Serverless template and going to the Network Configuration page.
利用可能状況
The IP ranges can sometimes change as a result of infrastructure deployments. To help keep you on top of any changes, we have compiled a list of up-to-date static IP ranges, in the following tables.
コミュニティ ユーザー
| リージョン | CIDR | IP 範囲 |
|---|---|---|
| 欧州 | | |
Enterprise ユーザー
| リージョン | CIDR | IP 範囲 |
|---|---|---|
| オーストラリア | | |
| 米国 | | |
| 日本 | | |
| 欧州 (欧州連合) | | |
Automation Hub
ドメイン
Allow the domains required for the Automation Hub functionality that your organization uses:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Automation Hub | https://cloud.uipath.comhttp://*.userpilot.iohttps://dc.services.visualstudio.comhttps://ah-prod-ts-blue-eu.uipath.comhttps://ah-prod-ts-blue-us.uipath.comhttps://ah-prod-ts-blue-ja.uipath.comhttps://ah-prod-ts-blue-au.uipath.comhttps://ah-prod-ts-blue-ca.uipath.comhttps://ah-prod-ts-blue-sea.uipath.comhttps://ah-prod-ts-blue-uk.uipath.comhttps://ah-prod-ts-blue-in.uipath.comhttps://ah-gxp-ts-blue-us.uipath.com | Automation Hub may not load. If Userpilot is blocked, first-time guidance is unavailable. If the telemetry endpoint is blocked, support telemetry is unavailable. |
| Use the Automation Hub Open API | https://automation-hub.uipath.comhttp://ah-gxp-openapi-us.uipath.com | Optional. Automation Hub Open API calls fail. |
Automation Ops
ドメイン
Allow the domains required for the Automation Ops functionality that your organization uses:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Automation Ops | https://stdadmstgcdn.azureedge.nethttps://stdadmstgcdn.blob.core.windows.nethttps://nexus.ensighten.comhttps://cloud.uipath.comhttps://platform-cdn.uipath.comhttps://use.typekit.nethttps://p.typekit.nethttps://content.usage.uipath.comhttps://data.usage.uipath.comhttps://*.service.signalr.netwss://*.service.signalr.nethttps://s.gravatar.comhttps://i2.wp.com | Automation Ops does not load or render correctly, and real-time updates are unavailable. |
| Use Source Control | https://github.comhttps://github.githubassets.comhttps://avatars.githubusercontent.comhttps://collector.github.comhttps://api.github.com | Source Control does not work. |
| Use Pipelines and send telemetry | https://app.vssps.visualstudio.comhttps://dc.services.visualstudio.com | Pipelines do not work. Blocking the telemetry endpoint also prevents support telemetry from being collected. |
IP 範囲
The table below lists all IP ranges used by Automation Ops.
| リージョン | IP 範囲 |
|---|---|
| オーストラリア | |
| 日本 | |
| 米国 | |
| United States — delayed update (GxP) | |
| 欧州 | |
| European Union — delayed update (GxP) | |
| カナダ | |
| シンガポール | |
| インド | |
| 英国 | |
IXP
ドメイン
Allow the domains required for IXP:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open IXP and authenticate | https://cloud.uipath.com | IXP is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.com | Some interface elements may not render correctly. |
| Receive real-time portal updates | *.service.signalr.net | Notifications and other portal updates do not appear until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.comhttps://dc.services.visualstudio.com | Core functionality remains available, but business telemetry and diagnostic logs are unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | IXP remains available, but onboarding and interactive help are unavailable. |
| Send performance-monitoring data | https://o486811.ingest.sentry.io | No user-facing functionality is affected, but performance diagnostics are unavailable. |
受信 IP 範囲
このセクションは、従来の Re:infer のユーザーにのみ適用されます。
IXP を使用してコネクションを作成するには、許可リストに次の受信 IP 範囲を追加します。
| リージョン | 受信 IP 範囲 |
|---|---|
| 欧州 | 34.91.100.206 |
| 米国 | |
| 日本 | 34.84.144.176 |
| オーストラリア | 35.189.46.91 |
| カナダ | 34.152.10.176 |
| シンガポール | 35.240.179.214 |
IP 範囲
IXP が Exchange からメールを同期するために、次の IP 範囲を許可します。Exchange との連携の概要について詳しくは、こちらをご覧ください。
| リージョン | IP 範囲 |
|---|---|
| 欧州 | 35.204.220.118 |
| 米国 | 34.71.173.219 |
| 日本 | 34.84.107.92 |
| オーストラリア | 34.87.223.173 |
| カナダ | 34.152.42.160 |
| シンガポール | 34.143.128.81 |
Data Fabric
ドメイン
Allow the domains required for Data Fabric:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Use Data Fabric | https://cloud.uipath.com | Data Fabric is unavailable. |
| Send service telemetry | *.visualstudio.com | No user-facing functionality is affected, but service telemetry is unavailable. |
Document Understanding
ドメイン
Allow the domains required for the Document Understanding functionality that your organization uses:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Document Understanding を開きます。 | https://*.uipath.com | Document Understanding does not load. |
| Send optional Azure telemetry | https://*.azure.com | Optional. Core functionality remains available, but telemetry used to investigate issues is unavailable. |
| Load the frontend | https://*.azureedge.net | Document Understanding does not load. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates do not appear until the page is refreshed. |
| Access legacy Document Manager storage | https://*.blob.core.windows.net | Document Manager does not work for projects created before 2023. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-product announcements and interactive guidance are unavailable. |
| Access public endpoints | See Public endpoints for the full list. | Information about predefined models and other public-endpoint functionality is unavailable. |
The legacy Document Manager storage domains apply only to projects created before 2023.
Cloudflare の IP 範囲フォールバック
ネットワーク機器が DNS ベースの許可リストをサポートしていない場合は、フォールバックとして Cloudflare の IP 範囲 104.16.0.0/13 を使用できます。Cloudflare の IP 範囲は広範で変更される可能性があるため、DNS ベースの許可リストに登録することをお勧めします。
Insights
ドメイン
次の表に、Insights で使用されるドメインを示します。
| シナリオ | 許可するドメイン | Impact if blocked |
|---|---|---|
| Insights のページに移動します。 | https://cloud.uipath.comhttps://*.lookercdn.comhttps://uipath-insights-statics.azureedge.net/https://*.looker.uipath.com/ | Insights may not load, and some dashboards or visualizations may be blank. |
IP 範囲
IP 範囲を使用すると、[ログをエクスポート] 機能と [データ エクスポート] 機能の IP のリストを許可リストに追加し、ネットワークをどの外部 IP に対しても開かないようにすることができます。BLOB ストレージのリージョンがそれぞれの Insights サービスのリージョンに対応している場合、パブリック IP は使用できません。
| Insights サービスのリージョン | BLOB ストレージのリージョン | 機能 | 静的 IP 範囲 |
|---|---|---|---|
| 欧州 |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| アメリカ合衆国 |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| オーストラリア |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| 日本 |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| カナダ |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| シンガポール |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| インド |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| 英国 |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| United States — delayed update (GxP) |
| ログのエクスポート | 134.33.240.104 |
| データ エクスポート | | ||
| Looker の SFTP 通知 | | ||
| European Union — delayed update (GxP) |
| ログのエクスポート | |
| データ エクスポート | | ||
| Looker の SFTP 通知 | |
制限事項
[ログをエクスポート] では、Google Storage は受信 IP 制限をサポートしません。
[ログをエクスポート] では、Microsoft 側の制限により、Azure Blob Storage アカウントと Insights インフラストラクチャが Azure の同じリージョンにある場合、受信 IP 制限を設定できません。このため、Insights サービスのリージョンに基づき、以下のリージョンは BLOB ストレージ アカウントに使用できません。
- Insights 米国: 北ヨーロッパ、米国東部
- Insights 欧州: 北ヨーロッパ、西ヨーロッパ (Community ライセンスの場合)
- Insights 英国: 北ヨーロッパ、英国南部
- Insights カナダ: 北ヨーロッパ、カナダ中部
- Insights シンガポール: 北ヨーロッパ、東南アジア
- Insights インド: 北ヨーロッパ、中央インド
- Insights オーストラリア: 北ヨーロッパ、オーストラリア東部
- Insights 日本: 北ヨーロッパ、東日本
- Insights — European Union — delayed update (GxP): North Europe, East US
- Insights — United States — delayed update (GxP): East US
この制限について詳しくは、Microsoft Azure Blob Storage のドキュメントの「Restrictions for IP network rules」のページをご覧ください。
Integration Service
IP 範囲
Add the following IP ranges to your allow list to use Integration Service and create connections, as described in the following table.
| リージョン | IP 範囲 | 環境 |
|---|---|---|
| オーストラリア | | Production |
| カナダ | | Production |
| 欧州 | | Production |
| 日本 | | Production |
| インド | | Production |
| シンガポール | | Production |
| 英国 | | Production |
| 米国 | | Production |
| United States — delayed update (GxP) | | Production |
| Community | | Production |
アスタリスク () が付いている IP アドレスは、新しく組み込まれた Azure リージョン用です。これらの IP は、スケジュールされたテナント移行プロセスが完了した時点で既存のリージョン IP を置き換えます。詳しくは、 Integration Service のリリース ノートをご覧ください。
Orchestrator
ドメイン
Allow the domains required for Orchestrator and Robot functionality:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Orchestrator | https://cloud.uipath.comhttps://orch-cdn.uipath.comhttps://account.uipath.com | The Orchestrator frontend does not load. |
| Connect Cloud Robots - VM to UiPath services | https://cloud.uipath.com | The Robot and agent on the provisioned VM cannot communicate with UiPath services. |
| Download Studio and Robot installers for Cloud Robots - VM | https://download.uipath.com | Optional if you install and manage the Robot yourself. Otherwise, Studio and Robot installers cannot be downloaded. |
| Access Orchestrator storage | *.blob.core.windows.netAmazon S3 バケットを使用する場合: *.s3.amazonaws.com | Package upload and download, suspended jobs, video recording, storage buckets, and other storage-backed functionality do not work. Provisioned Cloud Robots - VM also cannot connect to UiPath infrastructure. |
| Download packages and libraries | https://pkgs.dev.azure.com | Libraries and packages from the host feed cannot be downloaded. |
| Use Azure SignalR | https://*.service.signalr.netwss://*.service.signalr.net | Real-time updates and live streaming fail, attended jobs cannot be stopped remotely, and some Robot or activity events can be delayed by up to 30 seconds. |
| Update Studio and Robot automatically | https://download.uipath.com | Studio and Robot cannot update automatically. |
| Use Live Streaming and Remote Control | *.uipath.comhttps://*.uipath.comwss://*.uipath.com | Live Streaming and Remote Control do not work. |
IP 範囲
We recommend allowing these IP ranges, which send traffic from Orchestrator towards your resources. For details, refer to Orchestrator IP ranges.
コミュニティ ユーザー
| リージョン | CIDR | IP 範囲 |
|---|---|---|
| 欧州 (欧州連合) | | |
Enterprise ユーザー
| リージョン | CIDR | IP 範囲 |
|---|---|---|
| オーストラリア | | |
| カナダ | | |
| 米国 | | |
| 日本 | | |
| 欧州 (欧州連合) | | |
| シンガポール | | |
| 英国 | | |
| インド | | |
Delayed update (GxP) organizations
| リージョン | CIDR | IP 範囲 |
|---|---|---|
| 欧州 (欧州連合) | | |
| 米国 | | |
MCP サーバー
The remote MCP Servers service uses the IP ranges listed below for all external communications. The following table shows the available IP ranges for each region.
| リージョン | IP 範囲 |
|---|---|
| 欧州 | |
| 欧州 (セカンダリ) | |
| 欧州 - Community | |
| 欧州 - Community (セカンダリ) | |
| 米国 | |
| 米国 (セカンダリ) | |
| カナダ | |
| カナダ (セカンダリ) | |
| シンガポール | |
| 日本 | |
| 日本 (セカンダリ) | |
| オーストラリア | |
| オーストラリア (セカンダリ) | |
| インド | |
| インド (セカンダリ) | |
| 英国 | |
| 英国 (セカンダリ) | |
| European Union — delayed update (GxP) | |
| European Union — delayed update (GxP), secondary | |
| United States — delayed update (GxP) | |
| United States — delayed update (GxP), secondary | |
Process Mining
ドメイン
Allow the domains required for Process Mining:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Process Mining | https://cloud.uipath.com | Process Mining is unavailable. |
| Load static assets | https://fonts.googleapis.comhttps://fonts.gstatic.comhttps://content.usage.uipath.comhttps://s.gravatar.comhttps://i1.wp.com | Process Mining may not load or render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | The interface can display outdated information until the page is refreshed. |
| Send service telemetry | https://*.in.applicationinsights.azure.com | Optional. Core functionality remains available, but diagnostic information used for support is unavailable. |
| Upload data to Process Mining | *.blob.core.windows.net | Process Mining cannot ingest data or create process apps. |
Solutions (ソリューション)
ドメイン
Allow the domains required for Solutions Management:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Solutions Management | https://cloud.uipath.comhttps://fonts.googleapis.comhttps://fonts.gstatic.comhttps://dc.services.visualstudio.comapi.smartling.comuse.typekit.netp.typekit.nets.gravatar.comi2.wp.comhttps://platform-cdn.uipath.comhttps://sol-cdn.uipath.comhttps://solutions.uipath.com | Solutions Management or required interface assets may be unavailable. |
| Upload or download solution packages | *.blob.core.windows.net | Solution packages cannot be uploaded or downloaded. |
| Receive live deployment updates | https://*.service.signalr.netwss://*.service.signalr.net | Live status updates, including deployment progress, do not appear until the page is refreshed. |
Studio Web
ドメイン
Allow the domains required for Studio Web:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Receive real-time collaboration updates | wss://*.service.signalr.nethttps://*.service.signalr.netwss://*.trafficmanager.net | Live updates for project imports, shared projects, and other notifications are unavailable. |
| Open Studio Web | https://*.uipath.com | Studio Web is unavailable. |
| Send in-app feedback | https://studio-feedback.azure-api.net | In-app feedback cannot be submitted. |
| Load static assets | https://platform-cdn.uipath.comhttps://content.usage.uipath.comhttps://fonts.gstatic.comhttps://d2c7xlmseob604.cloudfront.nethttps://fonts.googleapis.comhttps://*.typekit.nethttps://s.gravatar.comhttps://secure.gravatar.comhttps://*.wp.comhttps://*.googleusercontent.comhttps://i.ytimg.com | Fonts, icons, images, or other static assets may not render correctly. |
| Send product telemetry | https://data.usage.uipath.com | Optional. Core functionality remains available, but product telemetry is unavailable. |
| Use Pendo in-app guidance | https://*.pendo.io | Optional. In-app guidance is unavailable. |
| Send third-party telemetry | https://dc.services.visualstudio.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load translated interface content | https://api.smartling.com | Translated interface content may be unavailable. |
Task Mining
ドメイン
Allow the domains required for Task Mining desktop components:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Task Mining | https://cloud.uipath.com | Task Mining is unavailable. |
| Use the web portal | *.blob.core.windows.net | The Task Mining web portal does not function correctly. |
| Receive desktop-component notifications | *.service.signalr.net | The desktop component may not receive real-time updates. |
| Use Pendo in-app guidance | https://content.usage.uipath.com | In-app guidance is unavailable. |
| Send Azure Application Insights telemetry | dc.services.visualstudio.comdc.applicationinsights.azure.comdc.applicationinsights.microsoft.com*.in.applicationinsights.azure.comlive.applicationinsights.azure.comrt.applicationinsights.microsoft.comrt.services.visualstudio.com{region}.livediagnostics.monitor.azure.com | Core functionality remains available, but diagnostic telemetry is unavailable. |
| Load user avatars | i2.wp.com/cdn.auth0.com/avatars | User avatars do not render. |
Task Mining uses HTTPS and WSS over port 443. Configure transparent proxies to permit both protocols.
Test Manager
This section lists the domains used by Test Manager and the IP ranges that you should consider allowing if you want to use various Test Manager capabilities.
ドメイン
Allow the domains required for Test Manager:
| Scenario or functionality | 許可するドメイン | Impact if blocked |
|---|---|---|
| Open Test Manager | https://cloud.uipath.com | Test Manager is unavailable or its interface does not render correctly. |
| Receive real-time updates | https://*.service.signalr.netwss://*.service.signalr.net | Some interface updates do not appear until the page is refreshed. |
SAP Heatmap and CIA RFC IP ranges
Allow the following IP ranges to establish communication between UiPath Test Manager and your SAP system via an RFC connection.
The following table shows the available IP ranges for each region.
| リージョン | IP 範囲 |
|---|---|
| オーストラリア | |
| カナダ | |
| 欧州 (欧州連合) | |
| インド | |
| United States — delayed update (GxP) | |
| 日本 | |
| シンガポール | |
| 英国 | |
| 米国 | |
SAP Heatmap and CIA Web Service IP ranges
Allow the following static IP ranges to enable the communication between UiPath Test Manager and your SAP system, via a web service connection.
Allow these IP ranges through your firewall:
| リージョン | IP 範囲 |
|---|---|
| オーストラリア | |
| カナダ | |
| Community | |
| 欧州連合 | |
| European Union — delayed update (GxP) | |
| インド | |
| 日本 | |
| シンガポール | |
| 英国 | |
| 米国 | |
| United States — delayed update (GxP) | |
IP ranges for connectors
If you enhance your system's security with a firewall, consider allowing only Test Manager IP ranges for using out-of-the-box connectors.
The following IP ranges apply to all supported regions, including: Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP).
Allow these IP ranges through your firewall:
| リージョン | IP 範囲 |
|---|---|
| Australia, Canada, European Union, India, Japan, Singapore, United Kingdom, United States, and United States — delayed update (GxP) | |
- 非推奨化のお知らせ
- 変更点
- タイムライン
- 以下を実行する必要があります
- Test Cloud ポータル
- ドメイン
- IP ranges to enable a firewall for the customer-managed key
- IP ranges for notifications
- Relay
- Action Center
- ドメイン
- AI Center
- ドメイン
- AI Computer Vision
- AI Trust Layer – 独自の LLM を使用する
- IP 範囲
- Apps (アプリ)
- ドメイン
- IP 範囲
- 許可リストに追加するコンテンツの種類
- Automation Cloud ロボット - サーバーレス
- IP 範囲
- Automation Hub
- ドメイン
- Automation Ops
- ドメイン
- IP 範囲
- IXP
- ドメイン
- 受信 IP 範囲
- IP 範囲
- Data Fabric
- ドメイン
- Document Understanding
- ドメイン
- Cloudflare の IP 範囲フォールバック
- Insights
- ドメイン
- IP 範囲
- Integration Service
- IP 範囲
- Orchestrator
- ドメイン
- IP 範囲
- MCP サーバー
- Process Mining
- ドメイン
- Solutions (ソリューション)
- ドメイン
- Studio Web
- ドメイン
- Task Mining
- ドメイン
- Test Manager
- ドメイン
- SAP Heatmap and CIA RFC IP ranges
- SAP Heatmap and CIA Web Service IP ranges
- IP ranges for connectors