Restrict Access to Claude Outside of Venn’s Blue Border

You can restrict access to Claude so that it can only be used securely in Blue Border. There are two ways to accomplish this:

  1. Using Claude’s IP Allowlisting Feature: Claude’s native IP Allowlisting feature can be used to restrict access to your organization’s Claude account so that only requests from approved IP addresses are allowed. Learn how to restrict access using Claude’s IP Allowlisting feature below.
  2. Via Identity Provider (IdP): Most IdPs like Microsoft Entra and Google can be used to restrict login access to connected apps based on IP address. IdPs often allow you to apply more granular restrictions than Claude’s native solution. Learn how to set up SSO for your Claude account here and learn how to set IP restrictions via IdP here.

When possible, we recommend applying IP restrictions via your IdP rather than applying the restrictions within individual business applications. 

Keep in mind that Claude’s native solution applies restrictions to your entire Claude organization on all device types, so it may not be a suitable solution if some of your employees don’t work in Blue Border or if some employee devices aren’t secured by Venn (e.g., if you aren’t using Venn’s MDM solution for phones).

IdPs typically allow you to apply more granular restrictions than Claude’s native solution (e.g., only apply restrictions to specific users or device types).

Plan Requirements

Visit this Claude resource to learn more about license requirements.

In order to use IP Allowlisting, your organization must be on the following Claude plan:

  • Claude Enterprise

Claude Free, Pro, Max, and Team plans do not include IP Allowlisting.

Claude Resources

Approach

  1. Gather your PCG IP addresses.
  2. Reach out to your Anthropic Contact or the Anthropic Sales team with your list of CIDR ranges and ask them to enable IP Allowlisting for your organization. (Claude doesn’t have a self-service page for this feature, but Anthropic can configure it on your account directly. Learn more here.)

Warnings

  • IP Allowlisting applies to your entire Claude organization — it can’t be scoped to a specific user group or a subset of users the way an identity provider’s app sign-on policy can. If not all of your users work in Venn, consider restricting login access through your IdP instead.
  • Keep in mind that there may be use cases and exceptions that you are not aware of or there may be individuals at your organization who were not fully onboarded to Venn.

Tips

  • If your organization uses an identity provider (like Entra ID, Google Workspace, Okta, JumpCloud, or Auth0) for Claude SSO, we typically recommend using that provider’s app sign-on or conditional access restrictions instead of Claude’s native restrictions.

Was this article helpful?