
The ALIS portal of BNP Paribas centralizes HR management, payroll, and career tracking for the group’s employees. Its access architecture has significantly evolved in recent years, with a federated authentication layer that regularly poses difficulties for employees, especially when working remotely.
Technical Access Architecture of the ALIS BNP Paribas Portal
Access to ALIS relies on a three-link authentication chain: mandatory group VPN, identity federation via login.extidp.bnpparibas, and then multi-factor authentication (MFA). Each request is verified to ensure it originates from the internal network before allowing the display of the HR portal at alis.hr.bnpparibas.
You may also like : Everything You Need to Know About the Price per Square Meter of Double Glazing and the Criteria to Consider
This SSO (Single Sign-On) architecture with group IDP means that an employee attempting to connect without an active VPN will have their request rejected before even reaching the login screen. The frequently reported error message ERR_BLOCKED_BY_CLIENT usually stems from an unestablished VPN tunnel or a browser extension interfering with the domain extidp.bnpparibas.
We recommend systematically checking three points before any attempt to connect to Alis BNP Paribas from a remote workstation: the VPN must show a connected status, the browser must not block third-party cookies from the bnpparibas domain, and the MFA must be set up on an up-to-date device.
Read also : Everything You Need to Know About the Evaluation and Criteria for Professional Titles in France

Security Escalation Procedure for Suspected ALIS Blockages
Not all blockages are the same. A classic login failure falls under the IT helpdesk. However, certain signals require a different circuit.
In case of redirection to a domain other than alis.hr.bnpparibas, unusual security alerts in the browser, or inconsistent geolocation displayed during the access attempt, the internal procedure mandates priority contact with the group’s CERT (Computer Emergency Response Team). This reflex should precede any call to the regular helpdesk.
The CERT qualifies the incident from a cybersecurity perspective: targeted phishing attempt, session compromise, or simple network anomaly. This distinction is crucial because a late report of a real security incident exposes the employee and the group to the risk of leaking personal HR data (pay slips, bank details, family situation).
Signals Justifying CERT Contact Instead of Helpdesk
- Redirection to a URL that does not end with .bnpparibas or .hr.bnpparibas, even if the visual appearance of the page seems identical to the ALIS portal
- Request for credential entry on a page lacking a valid SSL certificate for the group domain
- MFA notification received without a connection attempt from the employee, indicating an ongoing credential theft
- Abnormal geolocation message (connection detected from a country where the employee is not located)
Extended Maintenance of the ALIS Portal: Situation and HR Alternatives
The ALIS portal has been officially under maintenance since July 2024. The message displayed on alis.hr.bnpparibas mentions a suspension with no reopening date, under the responsibility of the RHG GAP teams. This unprecedented situation in its duration disrupts access to pay slips, leave tracking, and internal mobility processes.
During this period, employees must turn to their local HR manager for any requests usually handled in self-service on ALIS. Managers, who normally have a dedicated space to validate leave and manage their team’s interviews, are also forced to resort to manual circuits.
Data Accessible via ALIS in Normal Operation
To measure the impact of this unavailability, here is what the portal centralizes under normal circumstances:
- Consultation and downloading of pay slips, with a history spanning several years
- Management of leave and absences (requests, balances, manager validation)
- Tracking of administrative status: job scope, hierarchical attachment, personal data
- Access to career management tools: annual reviews, internal mobility, training
All of this data remains stored and secured despite the unavailability of the interface. The maintenance only concerns the application layer, not the group’s HR databases.

Remote Work and ALIS Access: Common Configuration Errors
Remote work has multiplied access incidents to ALIS. The majority of tickets opened with support concern remote workstation configuration issues, not failures of the portal itself.
The first reflex should be to check that the group VPN is connected before opening the browser. Launching the browser and then activating the VPN is not always sufficient: some DNS sessions remain cached and point to an external resolution of the domain alis.hr.bnpparibas, causing a silent blockage.
The second point concerns personal browsers. Ad blocker or tracker extensions regularly intercept requests to login.extidp.bnpparibas, which they classify as third-party domains. We observe that temporarily disabling these extensions, or using a dedicated browser profile without extensions, resolves the vast majority of cases.
Security of Personal Data in Remote Access
Accessing ALIS from a home network or shared Wi-Fi exposes employee data if the VPN is not active. The information passing through the portal (social security number, bank details, family situation) falls under GDPR and the group’s data protection scope.
Access without an active VPN circumvents the group security policy, even if the connection technically succeeds. The fact that the page displays does not guarantee that the channel is end-to-end encrypted according to BNP Paribas’s internal standards.
The resumption of the ALIS portal remains contingent on the work of the RHG GAP teams, with no public timeline. In the meantime, maintaining rigorous connection hygiene (systematic VPN, up-to-date MFA, vigilance on domains) protects both the employee and the company against risks related to the dematerialized management of HR and payroll data.