Anthropic Organization IP Restriction Deleted
Description
Organization IP restrictions limit Anthropic administrative access to approved network ranges. Deleting one widens where a compromised admin session or API key can be used. The audit event does not always carry the deleted CIDR or restriction identifier, so treat this as an early signal and pivot to nearby IP restriction create or update events for the same organization.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action == "org_ip_restriction_deleted"
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.idanthropic.audit.actor.typeuser.emailuser.idsource.ipuser_agent.original
Known false positives
- Network or security teams remove IP restrictions during office moves, VPN migrations, or policy redesigns. Validate the actor, and confirm replacement restrictions were applied if the control is still required.
Analyst notes
Investigating Anthropic Organization IP Restriction Deleted
IP allowlists limit where admin sessions and admin API keys can be used. Deleting a restriction widens that surface. The delete event often lacks the removed CIDR — recover it from nearby create/update events.
Unauthorized = no network/security change ticket for allowlist work, no replacement org_ip_restriction_created /
org_ip_restriction_updated in the same window, or deletion paired with admin key creation / SSO weakening.
Possible investigation steps
- Identify actor type. For
user_actor, check admin identity viauser.email,source.ip, and UA. Foranthropic_actor, pivot onorganization.idonly. - Search the same org for
org_ip_restriction_created/org_ip_restriction_updatedbefore/after the delete to recover ranges and see if this was a replace vs a standalone removal. - Correlate ±hours for admin role grants, admin API key creation, SSO changes, or data exports — common follow-ons after network controls drop.
- Close as FP when a ticket names the migration and a replacement restriction appears promptly. Escalate when deletion stands alone or admin activity from non-corporate IPs follows.
False positive analysis
- Office moves and VPN redesigns often remove old ranges before new ones are applied.
Response and remediation
- On unauthorized deletion: restore required IP restrictions, review admin activity from non-corporate
source.ipduring the open window, and rotate admin credentials / API keys used in that period.