Tenant Restrictions (Account Access) Data Loss Prevention Policy

The Tenant Restrictions Data Loss Prevention (DLP) Policy controls which accounts users can sign in with when they access software suites and AI tools inside Venn's Blue Border. Restricting these tools to your company's accounts keeps your users from signing in with unapproved accounts and moving company data outside of a workspace you control.

The existing Account Access policy will be replaced by our new Tenant Restrictions policy on September 15th, 2026. If previously configured, your Account Access Policy settings for Google Workspace and Microsoft 365 will carry over unchanged to the new Tenant Restrictions policy.

As a Company Manager, you can determine which accounts your users can sign in with for each supported tool as part of your Default Policy that applies to all users. You can also create Policy Overrides to change these settings for specific users or groups as needed.

Learn how to manage Default Data Loss Prevention Policies and Overrides.

View and Manage Your Tenant Restrictions Data Loss Prevention Policies

To view and manage your Tenant Restrictions DLP Policies:

  1. Navigate to the Admin Portal.
    • In your browser, go to https://login.venn.com/ and sign in if prompted. Then, click Open Admin Portal.
    • From the desktop app, click the Open web app icon.png Open web app icon. Then, click Company Admin in the top right.
  2. Click Policy Admin and select DLP Policy in the left menu. 

You will see your default Tenant Restrictions policy applied to all users under Default policy.

  • To view details or make adjustments to the default policy, click Change.
  • You will see any policy exceptions under Policy overrides. Check to see if any of your Policy Overrides include different Tenant Restrictions settings. To view details or make adjustments, click Edit next to the Policy Override.
  • You can also add additional Policy Overrides, which allow you to set DLP Policies that supersede the default policy for a single user or a group of users, as needed. For example, if a team in your organization works with an external client's Google Workspace tenant, you may want to set up a Policy Override that allows that tenant for those users rather than allowing it for everyone.

Learn how to manage Default Data Loss Prevention Policies and Overrides.

Tenant Restrictions Policy Options

Productivity Suites

Tenant Restrictions are available for Microsoft 365 and Google Workspace. For each tool, you can choose from the following options:

  • Don't allow access: Access is blocked completely.
  • Allow access with specific business accounts: Users can only sign in with an account linked to a domain or tenant that you specify.
    • For Microsoft 365, input a name for the tenant and provide the tenant ID.
    • For Google Suite, simply provide the domain(s).
  • Allow access with any account: Users can sign in with any business account. Users are always prevented from signing in from personal accounts.

The default for Productivity Suites is Don't allow access

You must have specific plan types to implement tenant restrictions:

  • Microsoft Entra requires
    • A Microsoft 365 Enterprise, Business Premium, or Frontline plan
    • Or Standalone Microsoft Entra ID P1/P2 Licenses
  • Google Workspace requires a Business or Enterprise plan

AI Tools

Tenant Restrictions are available for ChatGPT and Claude. For each tool, you can choose from the following options:

  • Don't allow access: Access is blocked completely.
  • Allow access with specific business accounts: Users can only sign in with an account linked to an organization that you specify.
  • Allow access with any account: Users can sign in with any account, business or personal.

The default for Productivity Suites is Don't allow access

You must have specific plan types to implement tenant restrictions:

  • ChatGPT requires an Enterprise or Team plan
  • Claude requires an Enterprise plan
If access is blocked or if the user attempts to sign in with an account that doesn't match the organization ID provided in the Tenant restrictions policy, ChatGPT does not block sign-in for restricted accounts, it ChatGPT blocks all requests after sign-in instead. If they attempt to access with a restricted account, the user will find that the app doesn't respond without an error message. This is a limitation on ChatGPT's side and there is no workaround.

Configure Tenant Restrictions

To configure Tenant Restrictions:

  1. From the DLP Policy admin page, locate Tenant Restrictions.
  2. Open the policy that you would like to update.
    • To update your default policy, click Change next to Tenant Restrictions.
    • To update a policy override, click Edit next to the override to apply the restriction only to that user or group.
  3. Within the policy editor that appears, expand the tool you would like to set tenant restrictions for.
  4. Click the radio button next to the desired option. See Tenant Restrictions Policy Options above for definitions.
  5. If you select Allow access with specific business accounts, specify the domain, tenant, workspace, or organization for that tool.
    • You can specify multiple domains or organizations by separating them with the Enter key.
  6. Click Apply in the lower right-hand corner.
tenant-restrictions-policy.png

Once you apply your changes, users that the policy applies to will only be able to sign in to each restricted tool with an account that matches what you specified. Users who are in more than one group will have the strictest setting applied.

Was this article helpful?