logo

ZTCA Configuration: Restrict GitHub Enterprise access to trusted IPs using Entra Conditional Access

ID: a9898c78-06ec-5d7c-a859-105ea30d2844

STIX ID: report--a9898c78-06ec-5d7c-a859-105ea30d2844

Feed Name: ThreatLocker Blog

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

This article provides step-by-step guidance to restrict GitHub Enterprise access by IP using Microsoft Entra ID Conditional Access: it lists prerequisites (licenses, SSO configuration, static IPs, break-glass accounts), shows how to create Named Locations, build a Conditional Access policy that blocks sign-ins from untrusted IPs (initially in Report-only), validate via sign-in logs and the What If tool, and finally enable enforcement; it also notes differences for OIDC/EMU and recommends configuring GitHub's native IP allow list for full coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.