
Alis is the internal HR portal of BNP Paribas, used by employees to access their payslips, leave requests, and various administrative services. Since July 2024, this portal has displayed a maintenance message, complicating matters for employees accustomed to connecting outside the bank’s premises. The question of connecting to the Alis BNP Paribas extranet remotely remains recurrent, especially among teleworkers and mobile employees.
Extended maintenance of the Alis portal: what it changes for remote access
The domain alis.hr.bnpparibas has been displaying a clear message since July 2024: the portal is under maintenance, with no return date announced. The HRG GAP teams are mentioned as responsible for this suspension. For employees who relied on remote access, this situation necessitates finding alternative channels.
When an HR portal of this magnitude remains unavailable for so long, the usual procedure (username, password, possibly token) simply no longer works. Feedback from the field varies on this point: some employees report being redirected to direct HR contacts, while others were directed to temporary internal platforms. No official public communication details the procedure to follow during this period.
Attempting to force the connection to Alis BNP Paribas extranet during a maintenance phase leads nowhere, and it is better to turn to your nearby HR manager or the internal support service to obtain the necessary documents.

Multifactor authentication and Zero Trust policy at BNP Paribas
Beyond the specific case of Alis, BNP Paribas has gradually rolled out multifactor authentication (MFA) across all its extranets. This applies to both HR portals and payment platforms like Mercanet or real estate extranets. The adopted logic is based on a Zero Trust approach: each connection attempt is verified independently, regardless of the originating network.
In practice, connecting from home or from a coworking space is no longer sufficient with just a username-password pair. The system requires an additional factor: a physical token, validation on a smartphone via a dedicated app, or passing through a secure SSO. This additional layer aims to block fraudulent access, but it also complicates life for legitimate users who do not always have the right equipment.
Why the home network poses a problem
BNP Paribas’s access policies incorporate controls related to the device used and geolocation. A connection from a personal computer not registered in the bank’s IT inventory can trigger an automatic block, even with valid credentials.
- The device must be recognized by the system (certificate installed, prior registration with the IT service)
- The geolocation of the IP address is checked to detect unusual connections or those from high-risk countries
- Sessions are time-limited, with automatic disconnection after a shorter period of inactivity than internally
These mechanisms are not unique to Alis. They apply to all the extranets of the BNP Paribas group and directly stem from European regulatory requirements.
Impact of PSD2 on BNP Paribas extranet connections
The European Payment Services Directive (PSD2) requires financial institutions to implement strong customer authentication (SCA) for access to online services. BNP Paribas applies this requirement to its extranet portals, including those that do not directly handle financial transactions.
The documentation for Mercanet solutions explicitly mentions these enhancements. In practice, this translates to systematic device checks, geolocation controls, and reduced session durations for off-site connections. For a teleworking employee, this means anticipating: having their work smartphone at hand, using an up-to-date browser, and connecting from a reliable network.

Recommended security best practices by BNP Paribas for teleworking
BNP Paribas internally disseminates specific recommendations for employees accessing online services from home. These guidelines are not trivial and often determine the success of the connection.
- Use a secure private network (professional VPN if provided, or otherwise a home Wi-Fi network protected by a strong password)
- Update the operating system and browser before each connection attempt, as outdated versions may be rejected by the portal
- Disable browser extensions that may interfere with the authentication process (aggressive ad blockers, unauthorized third-party VPNs)
- Never save credentials in the browser on a shared device
These steps may seem basic, but an outdated extension or browser is enough to fail the connection, without an explicit error message. The portal then returns a blank page or a generic error that does not point to the real cause.
Alternatives and recourse in case of connection failure to Alis
As long as the maintenance of the Alis portal continues, BNP Paribas employees do not have direct access to this platform, whether from the internal network or from outside. The available data does not allow for confirmation of a reopening date.
To obtain HR documents (payslips, certificates), the preferred channel remains direct contact with the HR manager attached to your entity. Some services are also accessible via other internal group portals, depending on the subsidiaries. In case of doubt about the applicable procedure, the internal IT support service can guide you to the right platform.
The multiplication of security layers makes remote connections more reliable, but also more fragile in the face of configuration errors. Checking your equipment before contacting support often allows you to resolve the problem without technical intervention. If the blockage persists after these checks, it is likely a restriction related to the device or network, and only the IT service can lift this lock.