Restrict Access to ChatGPT Outside of Venn’s Blue Border

You can restrict access to ChatGPT so that it can only be used securely in Blue Border. There are two ways to accomplish this:

  1. Using ChatGPT’s Allowlisting Feature: ChatGPT's native IP Allowlisting feature can be used to restrict access to your organization’s ChatGPT workspace so that only requests from approved IP addresses are allowed. Learn how to restrict access using ChatGPT's Allowlisting feature below.
  2. Via Identity Provider (IdP): Most IdPs like Microsoft Entra and Google can be used to restrict login access to connected apps based on IP address. IdPs often allow you to apply more granular restrictions than ChatGPT's native solution. Learn how to set up SSO for your ChatGPT workspace here and learn how to set IP restrictions via IdP here.

When possible, we recommend applying IP restrictions via your IdP rather than applying the restrictions within individual business applications. 

Keep in mind that ChatGPT's native solution applies restrictions to all ChatGPT users in your workspace on all device types, so it may not be a suitable solution if some of your employees don't work in Blue Border or if some employee devices aren't secured by Venn (e.g., if you aren't using Venn's MDM solution for phones).

IdPs typically allow you to apply more granular restrictions than ChatGPT's native solution (e.g., only apply restrictions to specific users or device types).

Plan Requirements

Visit this OpenAI resource to learn more about license requirements.

In order to use IP Allowlisting, your organization must be on one of the following ChatGPT plans:

  • ChatGPT Enterprise
  • ChatGPT Edu

ChatGPT Free, Plus, Pro, and Business (formerly ChatGPT Team) plans do not include IP Allowlisting.

OpenAI Resources

Approach

  1. Gather your PCG IP addresses.
  2. In your ChatGPT workspace settings, set a IP Allowlist for Workspace or Compliance API under Access Restriction (instructions here).

Warnings

  • IP Allowlisting applies to your entire ChatGPT workspace — it can’t be scoped to a specific user group or a subset of users the way an identity provider’s app sign-on policy can. If not all of your users work in Venn, consider restricting login access through your IdP instead.
  • When these restrictions are in place, users can still sign in and switch between workspaces from outside your PCG IP addresses. IP Allowlisting only blocks loading new data once they’re in the workspace.
  • Keep in mind that there may be use cases and exceptions that you are not aware of or there may be individuals at your organization who were not fully onboarded to Venn.

Tips

  • If your organization uses an identity provider (like Entra ID, Google Workspace, Okta, JumpCloud, or Auth0) for ChatGPT SSO, we typically recommend using that provider’s app sign-on or conditional access restrictions instead of ChatGPT's native restrictions.

Was this article helpful?