Verified on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0).
You click "Send" for an ESF (e-invoice) in the ESF IS — and instead of a receipt you get: "Access to the resource is prohibited by the security profile." The database runs in client-server mode, security profiles are enabled on the cluster, and the server silently cuts off all outbound internet until a specific address is allowed. There is only one question: exactly which addresses, ports, and directories must be allowed so that ESF, SNT, bank exchange, counterparty verification, and updates work. The full answer lies in this report. It shows the complete list of external resources the configuration is at all capable of using — you just need to transfer them into the cluster's security profile.
Let us warn you right away: this is a service (technical) report, not an accounting document. It does not make postings, does not calculate VAT, does not generate ESF, and does not move registers. It is read by the administrator-accountant and the IT specialist when they set up access. Therefore there are no sections below about Dr/Cr "for real" — the report physically does not have them, and making them up would be a lie.
1. Purpose
The report collects and displays all external resources that the configuration accesses: internet addresses (for ESF, SNT, bank client, updates, BIN/IIN verification), file system directories, OS applications, external components, and COM objects. It is needed to correctly and without "holes" configure the security profile on the 1C:Enterprise server cluster.
2. Where to find it
The report is not located in the accounting sections ("Sales," "Purchases," etc.) — it is a system report. It can be opened in three ways:
- Main menu → "All functions" → "Reports" → "UsedExternalResources". If there is no "All functions" item — enable it: "Service and settings" → "Settings" → "Options" → check the box "Display the 'All functions' command".
- 1C navigation link. "Service and settings" → "File" → "Open" is not available for this; use the menu → "Go to navigation link" and paste:
(in some releases the report opens with a link of the forme1cib/list/Отчет.ИспользуемыеВнешниеРесурсыe1cib/report/ИспользуемыеВнешниеРесурсы— if the first one didn't work, try this one). - Through the configurator / administration console — when generating a security profile, the platform relies on the same list.
It makes sense to work with the report as a user with administrator rights. An ordinary accountant does not need it — until the server starts blocking the internet.
2a. How to find out your release
"Main menu" (icon at the top left) → "Help" → "About the program". In the window you will see:
- Platform version (for example, 1C:Enterprise 8.3.24.xxxx);
- Configuration: "Accounting for Kazakhstan," edition 3.0, release (for example, 3.0.74.2).
The release matters: the set of external resources changes from version to version (a new ESF IS service was added — a new address appeared). The instructions below have been verified on 3.0.74.2.
3. How to generate it and what to fill in
The report is informational: you open and read it, rather than "filling it in" like an invoice. There are minimal control fields.
| Element | Why | What happens if set incorrectly |
|---|---|---|
| "Generate" button (required action) | Builds the current list of resources for the current release | Until you click — the area is empty, and it seems there are "no resources" |
| Grouping / filtering by resource type | Collapse to the needed type (for example, only "Internet") | It is easy to "lose" a directory or application row if you leave a filter on |
| "Show only used" flag (if present in the release) | Hide theoretically declared but inactive resources | Too narrow a list → some addresses won't get into the profile → blocking |
What you read in the result (columns):
- Resource type — Internet, File system, OS application, External component, COM object, Privileged mode, Cryptography.
- Address / Path — the specific host (
esf.gov.kz,www.tradenet.kz, etc.) or directory. - Protocol — http, https, ftp, smtp, imap, pop3.
- Port — 443, 80, 25, 143, etc.
- Permission — Read / Write / Read and write (for directories).
- Purpose / Comment — what it is used for (ESF, SNT, exchange, update).
The key rule: each row is transferred into the security profile in its entirety — address + protocol + port. You allowed the host but forgot port 443 — the connection still won't open.
4. Worked example
Situation: a client-server database, a cluster with security profiles enabled, the accountant cannot send an ESF and update the configuration over the internet.
- You open the report → "Generate." You see a table like this:
| Type | Address / Path | Protocol | Port | Permission | Purpose |
|---|---|---|---|---|---|
| Internet | esf.gov.kz | https | 443 | — | Sending/receiving ESF |
| Internet | tradenet.kz | https | 443 | — | SNT, virtual warehouse |
| Internet | downloads.1c.ru | https | 443 | — | Configuration update |
| Internet | webits-info.gov.kz | https | 443 | — | BIN/IIN verification, taxpayer statuses |
| File system | %TEMP%\1C\Exchange | — | — | Read and write | Exchange upload/download |
| OS application | crypto-provider | — | — | Launch | Digital signature when signing ESF |
- You open the 1C server administration console → security profile of your database.
- On the "Internet resources" tab you add a row for each address: name (any), protocol
https, addressesf.gov.kz, port443. Repeat for tradenet.kz, downloads.1c.ru, webits-info.gov.kz. - On the "Directories" tab you add the exchange path with "Read" and "Write" rights.
- On the "External modules / applications" tab you allow the crypto provider (for the digital signature).
- You save the profile, repeat sending the ESF — it goes through.
Honestly about postings. This report creates no Dr/Cr movements: it posts nothing. Postings in "Accounting for Kazakhstan" are made by accounting documents. For comparison — a typical goods sale (invoice), for the sake of which access to ESF is configured, at VAT 16% generates:
- Dr 1210 Cr 6010 — revenue excluding VAT;
- Dr 1210 Cr 3130 — VAT 16% payable;
- Dr 7010 Cr 1330 — write-off of the cost of goods.
But those are movements of the sales document, not of the "UsedExternalResources" report. The report itself is only a directory of addresses and paths.
5. Types of "operations" (types of resources)
The report has no separate "operation types" like documents do. There are resource types that it classifies:
- Internet resources — outbound connections (ESF, SNT, updates, counterparty verification, e-mail sending).
- File system — directories for reading/writing (exchange, temporary files, uploads).
- OS applications — launching external programs (crypto providers, archivers).
- External components (add-in) — scanners, digital signature components.
- COM objects — integration with office applications.
- Privileged mode — code sections requiring extended rights.
- Cryptography — signing/encryption operations.
6. What is generated upon "posting"
The report is not posted. It does not create:
- Dr/Cr postings;
- electronic documents (ESF, SNT) — these are generated by accounting documents, not by it;
- movements in accumulation and information registers.
The only "result" is the table area on the screen, which you read and transfer into the cluster's security profile. Indirectly, based on it, the platform is able to automatically generate a security profile at the first publication/setup of the database.
7. Printed forms
The report has no separate form (like an invoice). Standard actions of a spreadsheet document are available:
- Print the generated list — "File" → "Print" (Ctrl+P);
- Save to a file: "File" → "Save as" → formats
.mxl,.xlsx,.pdf; - Copy selected rows to the clipboard for pasting into a request to the IT specialist.
Usually the list is saved to Excel/PDF and handed to the server administrator as a checklist of addresses for the profile.
8. Common mistakes
- "Access to the resource … is prohibited by the security profile" / "Violation of access rights to the resource". The cause is that an address from the report was not entered into the profile. Solution: reconcile the report with the profile, add the missing address/port.
- You allowed the host but not the port. The connection still breaks. Each internet resource is a bundle of address + protocol + port; port
443for https is mandatory. - "Report not found" via the navigation link. The form of the link depends on the release: try
e1cib/report/ИспользуемыеВнешниеРесурсыinstead ofe1cib/list/..., or open it via "All functions". - The list is empty. You didn't click "Generate," or there is too strict a filter by type — remove the filter.
- You configured the profile, but the ESF doesn't go out. Check the permission for the OS application/crypto provider and the temporary files directory — these are often forgotten when only the internet is allowed.
- You updated — and blocking again. After a release update, new addresses may have appeared in the report. Regenerate the report and supplement the profile.
9. FAQ
Is this an accounting document? Where are its postings? No. It is a service report. It makes no postings, VAT, or electronic documents — it only shows a list of external resources.
Why does the accountant need it? To understand which internet addresses and directories to allow when a server with security profiles blocks ESF, SNT, bank exchange, or updates.
Is it needed in a file-based (non-server) database? Practically no: security profiles are a mechanism of the server cluster. In a file-based database, access to the internet/files is limited only by OS and antivirus settings.
How to open it if there is no "All functions"?
Enable it: "Settings" → "Options" → "Display the 'All functions' command". Or go to the link e1cib/list/Отчет.ИспользуемыеВнешниеРесурсы.
Where to get the security profile itself?
In the 1C server administration console (or via the administration server ras/rac). The report provides the content, the profile is the place where this content is entered.
Why, after an update, does the ESF fail to send again? In the new release the service address may have changed or a new one been added. Regenerate the report and reconcile it with the profile.
Which addresses are needed specifically for ESF and SNT in Kazakhstan? At a minimum, the ESF IS resources (esf.gov.kz) and the virtual warehouse/SNT (tradenet.kz) over https, port 443. Always take the exact list from the report on your own release — it is more up to date than any memo.
Does the report affect amounts, VAT 16%, or taxes? No. It does not affect the calculation of VAT, IIT, mandatory pension contributions, or anything else — it is a purely technical list of resources.
Can the list be exported for the IT specialist? Yes: generate the report and save it to Excel or PDF ("File" → "Save as"), or print it.
Who should work with it? A user with administrator rights together with the specialist servicing the 1C server.
10. Related objects
- Security profile of the 1C server cluster — the main "recipient" of the report's data; configured in the administration console.
- Electronic document exchange settings (ESF/SNT) — their operation depends precisely on the allowed internet resources.
- Configuration update settings — use the update service address from the list.
- Sales documents / invoices (ESF) — not directly related to the report, but it is for the sake of sending them to the ESF IS that you configure access using this list.
How to find out your release. "Main menu" → "Help" → "About the program": there the platform version and the configuration release are indicated.
The material was prepared for "Accounting for Kazakhstan," edition 3.0, release 3.0.74.2. Kazakhstan indicators for 2026 (for reference on related accounting documents): VAT 16%, MCI 4,325 ₸, minimum wage 85,000 ₸, basic IIT deduction 30 MCI/month.
