---
title: "Tenant restriction examples"
canonical: "https://docs.aryaka.com/space/KNOW/1275789674/Tenant%20restriction%20examples"
format: markdown
---
This document describes tenant restriction for common SaaS application vendors.  Tenant restriction Tenant restriction allows you to intercept connections to specific SaaS applications and inject vendor-defined headers with user-defined values. These user-defined values are dependent on your organization and are typically tenant domain names, workspace IDs, or directory IDs. In addition to user-defined values, predetermined vendor-defined values are sometimes injected to enforce standard restrictions. For example, for tenant restriction v1, Microsoft expects you to inject the following header-value pair to block access to personal accounts: Header Value sec-Restrict-Tenant-Access-Policy restrict-msa To configure Tenant Restriction security rules in MyAryaka, you can  add site-level Tenant Restriction rules  or  create a Tenant Restriction ruleset . See the  CASB  topic for more details on tenant restriction and Aryaka SmartSecure CASB. Tenant restriction examples The following sections provide tenant restriction configuration examples for the following SaaS applications: Microsoft Slack Webex Dropbox Google Cloud Microsoft There are two versions of tenant restriction for Microsoft: v1 and v2. v1 The following table displays the request headers required to perform v1 tenant restriction for  login.microsoftonline.com ,  login.microsoft.com , and  login.windows.net : Header Value Restrict-Access-To-Tenants Comma separated list of domains and directory IDs of allowed tenants Restrict-Access-Context Directory ID of tenant setting the restriction If you want to block access to personal Microsoft accounts, you can use the following request header and vendor-defined value to perform tenant restriction for  login.live.com : Header Value sec-Restrict-Tenant-Access-Policy restrict-msa For additional details on v1 tenant restriction for Microsoft, see the Microsoft documentation on  Using tenant restriction to manage access to SaaS apps . v2 The following table displays the request header required to perform v2 tenant restriction for  login.microsoftonline.com ,  login.microsoft.com ,  login.windows.net , and  login.live.com : Header Value sec-Restrict-Tenant-Access-Policy Microsoft Entra tenant ID (Tenant ID) and the object ID for your cross-tenant access policy (PolicyID) in the format < TenantID >:< PolicyID > For additional details on v2 tenant restriction for Microsoft, see the Microsoft documentation on  Configuring tenant restrictions . Slack The following table displays the request headers required to perform tenant restriction for  Slack : Header Value X-Slack-Allowed-Workspaces-Requester One organization ID  or  workspace ID X-Slack-Allowed-Workspaces Comma separated list of all valid organization IDs and Workspace IDs supported by your organization For additional details on tenant restriction for Slack, see the Slack documentation on  Approving Slack workspaces for your network . Webex The following table displays the request header required to perform tenant restriction for Webex: Header Value CiscoSpark-Allowed-Domains Comma separated list of domains This header should be injected for each outgoing request to the following Webex domains: idbroker.webex.com idbroker-secondary.webex.com idbroker-b-us.webex.com idbroker-eu.webex.com atlas-a.wbx2.com idbroker-ca.webex.com For additional details on tenant restriction for Webex, see the Webex documentation on  Configuring a list of allowed domains . Dropbox The following table displays the request header required to perform tenant restriction for  Dropbox : Header Value X-Dropbox-allowed-Team-Ids Comma separated list of Dropbox team IDs For additional details on tenant restriction for Dropbox, see the Dropbox documentation on  Network control . Google Cloud The following table displays the request header required to perform tenant restriction for Google Cloud services: Header Value X-Goog-Allowed-Resources Comma separated list of allowed Google Cloud organization IDs and one of the following strings:   "strict" "cloudStorageReadAllowed" See the following section for formatting requirements for this value.  This header should be injected for each outgoing request to the following Google domains: *.google.com *.googleapis.com *.gcr.io *.pkg.dev *.cloudfunctions.net *.run.app *.tunnel.cloudproxy.app *.datafusion.googleusercontent.com  Header value format The header value must be base64 encoded and use the following JSON format: {
  "resources": [string,..],
  "options": string
  } This header includes the following attribute-value pairs: "resources" —Paired value is a comma separated list of the Google Cloud organization IDs that you want to allow. "options" —Paired value is one of the following two strings: "strict" —Enforces the tenant restrictions header for all request types to  supported Google Cloud services . "cloudStorageReadAllowed" —Enforces the tenant restrictions header for all request types to  supported Google Cloud services , but allows access for the following Cloud Storage read operations: storage.objects.get storage.objects.list storage.objects.getIamPolicy storage.buckets.get storage.buckets.list storage.buckets.getIamPolicy For additional details on tenant restriction for Google Cloud and for an example header value in the correct JSON format with base64 encoding, see the Google documentation on  Configuring organization restrictions . In this topic Related topics CASB Configure a Tenant Restriction ruleset