Tenant Restrictions

Tenant Restrictions allow administrators to control which tenants of supported SaaS applications users can access. This feature prevents users from accessing personal or unauthorized accounts on platforms such as Microsoft Office 365, Google Workspace, GitHub, Claude, ChatGPT, Dropbox, and Slack, ensuring that only organization-approved tenants are reachable from the corporate network.

To view the Tenant Restrictions page, access the SASE Administrator Portal and click Internet Access > Tenant Restrictions.

Supported Applications

Tenant Restrictions supports these applications:

  • Microsoft Office 365

  • Google Workspace

  • GitHub

  • Claude (Anthropic)

  • ChatGPT (OpenAI)

  • Dropbox

  • Slack

Policy Table Columns

Column Description
Cloud Service

Displays the cloud service for which the restriction is applied:

  • Microsoft Office 365

  • Google Workspace

  • GitHub

  • Claude (Anthropic)

  • ChatGPT (OpenAI)

  • Dropbox

  • Slack

For supported vendors, this column is auto-populated and cannot be edited.

Source

Defines the groups or members the restriction applies to:

  • Any (default) - Applies to all users.

  • Groups or Members - Applies to selected groups or users from your identity provider.

Allowed Identifiers

Specifies the tenant identifiers that users in the selected source are allowed to access. The accepted identifier format depends on the selected vendor.

Examples for Microsoft Office 365:

  • Standard domain: contoso.com

  • Microsoft domain: fabrikam.onmicrosoft.com

  • Tenant identifier: aaaabbbb-0000-cccc-1111-dddd2222eeee

See Allowed Identifiers.

Specify one or more domains explicitly in the allowed identifiers to ensure the restriction is applied as intended.