Navigate to: Admin > Users > Settings
Shepherd offers enhanced login security by allowing clinics to restrict access based on IP addresses. When enabled, only users connecting from approved IP addresses can log in. Clinic managers can configure this setting, receive alerts for unauthorized attempts, and view detailed logs of blocked access.
These restrictions currently apply to clinic login users only. IP-based restrictions for Group Platform logins are coming soon.
What You Need to Know
A static IP address is required before enabling this feature.
Enabling IP restrictions with a dynamic IP may result in being locked out of your Shepherd account. Confirm your IP type with your ISP or network administrator before proceeding.
Clinic Login IP Restrictions apply to the shared Clinic Login only. Remote
Access users log in with their own individual credentials and are not affected by this setting. They can continue to log in from any location regardless of whether IP restrictions are enabled.
An unauthorized login attempt is only recorded if the correct credentials were used.
Credentials are validated before the IP check runs. If the wrong password is entered, the IP check never executes and no log entry is created. An empty Unauthorized Login Attempts log does not mean access was not attempted.
Who Can Enable IP Address Restrictions
Only users with the User Setting permission can configure IP restrictions. This permission is granted by default to Admin and Practice Owner roles.
Check out our full article on user permissions:
Before You Enable: Confirm Your IP Type
IP restrictions lock Clinic Login access to specific IP addresses. If your clinic's IP address changes after enabling this feature, Shepherd will block access from that connection until the new IP is added by an Admin or Practice Owner.
Before enabling, confirm the following:
Ask your ISP or IT provider whether your clinic's public internet IP address is static.
In Shepherd, select Test My IP and note the IP address shown before making any changes.
Do not enable IP restrictions if your clinic uses a dynamic IP address unless your IT provider has a plan to keep access stable.
How to Enable Clinic Login IP Address Restrictions
Navigate to Admin > Users > Settings
Toggle on Enable Clinic Login IP Address Restrictions and select Save
Select IP Restrictions > General
Select Test My IP to view your current IP address
Add your current IP address to prevent being locked out and select Save
Allowed IP Addresses
Once enabled, only IP addresses saved within Shepherd will be permitted to log in. Users accessing from non-approved IP addresses will be denied access.
If you don't know your IP address, select Test My IP. If you want to add this IP to the Allowed IP Address list, select Yes, add this IP and then Confirm.
Use the IP shown by Test My IP in Shepherd — not the IP from Windows Command Prompt (ipconfig) or your device's network settings. Those show your private local network IP, which is not the same as the public IP address that Shepherd checks.
Only IPv4 addresses are supported.
Will This Stop Employees from Logging In from Home?
Clinic Login IP Restrictions are what prevent the shared Clinic Login from being used outside your approved IP addresses.
Disabling an employee's Remote Access does not prevent them from using the shared Clinic Login from home. If an employee knows the clinic's shared email and password, they can use those credentials plus their PIN to log in from any location — unless Clinic Login IP Restrictions are enabled.
Login type | Affected by Clinic Login IP Restrictions? |
Shared Clinic Login (email/password + PIN) | Yes |
Individual Remote Access login | No |
Group Platform login | No (restrictions coming soon) |
Clinic Login IP Restrictions do not control whether the Remote Access setting is editable for individual users. If the Remote Access checkbox appears grayed out on a user profile, this is a role or permissions issue unrelated to IP restrictions.
Unauthorized Access Attempts
Unauthorized Access Attempt Alerts (Optional)
To receive alerts when unauthorized login attempts occur:
Navigate to Admin > Users > IP Restrictions > Unauthorized Login Attempts
Under Send Unauthorized Access Attempt Alerts, enter one or more email addresses
All recipients will be notified when a blocked attempt is detected
Viewing Unauthorized Login Attempts
Unauthorized logins are logged automatically. Logs include the timestamp and blocked IP address. You can access this log under Admin > Users > IP Restrictions > Unauthorized Login Attempts.
If you see a blocked IP in the log that should be allowed, copy that IP address and compare it to your Allowed IP Address list. If the IP is missing or has changed, re-add it, select Save, and ask the user to try logging in again.
Troubleshooting Blocked Access
If a clinic device is blocked after enabling IP restrictions:
Try logging in from another device on the same clinic network. If that device works, the issue may be specific to the blocked device's connection rather than the IP address.
Try the blocked device on a different network, such as a mobile hotspot. If it works on another network, the IP from the original connection may not be in the allowed list.
Navigate to Admin > Users > IP Restrictions > Unauthorized Login Attempts and look for the blocked IP address in the log.
Select Test My IP from inside Shepherd on the affected connection and confirm the IP shown matches an entry in your Allowed IP Address list. If it doesn't match, add the new IP and save.
If the browser shows a 403 Forbidden error and Shepherd will not load at all, the issue may be a network-level block unrelated to IP restrictions. Contact your IT provider or Shepherd Support.
Frequently Asked Questions
Why didn't a blocked login attempt appear in Unauthorized Login Attempts?
Unauthorized login attempts are only recorded when the correct credentials are used. Credentials are validated before the IP check runs, so if the wrong password is entered, no IP check occurs and no log entry is created. If you expect to see a log entry but the list is empty, verify that the correct shared Clinic Login credentials are being used.
Can I add multiple IP addresses to the allowed list?
Yes, you can add multiple IP addresses to the Allowed IP Address list. [NEEDS CS VERIFICATION — confirm there is no cap on the number of IPs that can be added] To add additional addresses, navigate to Admin > Users > IP Restrictions > General, use Test My IP or enter each IP manually, and select Save. Each saved IP will be permitted to access the shared Clinic Login.
What happens if my IP address changes after I enable restrictions?
If your clinic's IP address changes after enabling restrictions, devices connecting from the new IP will be blocked. To restore access, an Admin or Practice Owner must log in from an already-approved IP address, navigate to Admin > Users > IP Restrictions > General, add the new IP, and select Save. This is why a static IP address is required before enabling this feature. If your IP changes frequently, contact your ISP or IT provider about obtaining a static IP.


