When you first enable a service, all users can connect to it from all network address ranges.
The following are exceptions:
Screen sharing and SSH: These are limited to users who are members of the Administrators group.
Caching: This is available to clients with private network IP addresses.
In order to limit service access to users, groups, and IP address ranges, you need to:
Define IP address groups (in other words, IP address ranges). See Create custom network access definitions.
Create or define groups whose members will use services. See Define service access by users.
Create other network access rules, as needed. See Edit custom network access rules.
If your custom access list gets too long, you can filter the list to find the item you need.