AEM as a Cloud Service: IP whitelisting for penetration testing

This article describes the process for requesting IP whitelisting to enable penetration testing on Adobe Experience Manager as a Cloud Service Stage or UAT environments.

Description description

Environment

Adobe Experience Manager as a Cloud Service (AEMaaCS) (all versions)

Symptoms

When conducting penetration testing on Stage or UAT environments, the testing team’s IP addresses is blocked by Adobe’s security controls, even if they are already whitelisted on the customer’s enterprise CDN. This can result in access issues during testing, although no specific error messages are shown.

Cause

Penetration testing IPs must be explicitly whitelisted through the official workflow to prevent automated security controls from blocking legitimate testing activities on AEM as a Cloud Service environments.

Resolution resolution

Follow the steps below to resolve the issue:

  1. Go to https://experience.adobe.com and select Experience Manager.
  2. Navigate to the Security and Compliance section in the side menu.
  3. Click on the Penetration Tests option. If this section isn’t visible, change your persona or preset to Admin or IT.
  4. Open the penetration testing request form.
  5. Provide all required details, including the planned testing dates and the list of IP addresses to be whitelisted.
  6. Submit the form for review.

The request will be reviewed by the appropriate Adobe team.

recommendation-more-help
experience-cloud-kcs-help-kbarticles