logo

Restrict GitHub access to a specific IP address using Conditional Access

ID: 87c2949b-998f-5cc3-b3ac-a47d6632ed5d

STIX ID: report--87c2949b-998f-5cc3-b3ac-a47d6632ed5d

Feed Name: ThreatLocker Blog

Date Published: 2026-05-07

Date Updated: 2026-05-07

...
...

### Executive summary This article provides step-by-step guidance to restrict GitHub Enterprise access to trusted IP addresses using Microsoft Entra ID Conditional Access: create Named Locations for approved IPs, build a Conditional Access policy that blocks sign-ins from non-trusted locations (validate in Report-only mode first), and enable the policy while excluding break-glass accounts; it also explains differences between SAML and OIDC flows and recommends configuring GitHub's native IP allow list to block non-SSO access methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.