Require Approved Accounts for AI Apps

Enforce company sign-in on AI apps from an Internet Threat Protection (ITP) policy in SonicWall Cloud Secure Edge (CSE)

  • Last validated: Sep 25, 2026
  • 8 minutes to read
  • Contributors

Preview feature: Require approved accounts is available as a preview. Review Limitations before you enable it, and expect behavior to change before the feature becomes generally available.

Overview

Require approved accounts enforces that users access AI apps with a company identity instead of a personal or anonymous account.

You enter the email domains your organization signs in with, for example sonicwall.com. CSE then inspects sessions to the supported AI apps, reads the signed-in identity, and blocks the prompt when the identity does not match one of your approved domains.

Enforcement covers all of the apps the console lists under Supported apps, and there is nothing to select per app. In this preview those apps are:

  • Microsoft Copilot
  • Claude
  • Google Gemini
    • Includes the AI answers built into Google Search: AI Overviews and AI Mode
  • ChatGPT

To request coverage for an app that is not on the list, contact your account team.

Where enforcement applies

Enforcement applies on both surfaces users reach these apps through:

  • Browsers. The app opened as a website, for example chatgpt.com or gemini.google.com, and the AI answers built into Google Search.
  • Desktop apps. The AI company’s own desktop client, for example the ChatGPT desktop app. The ChatGPT desktop app pins certificates and needs one extra step from you, on a managed device, before inspection works on it. See Certificate-pinned apps.

Why enforce approved accounts

Most organizations that buy a commercial AI contract still have users reaching the same tools through consumer accounts. The commercial contract is what gives you admin controls and an agreement that the provider will not train on your data. A consumer account gives you neither.

When a user sends company data to a consumer AI account, your organization is exposed to:

  • Model providers training on your data, and intellectual property or trade secrets being extracted from it
  • Compliance failures, because the usage falls outside the contract and controls you can demonstrate
  • Leaks of customer data, personally identifiable information (PII), and financial data

Require approved accounts closes that gap by making the corporate instance the only one users can submit prompts to.

How this differs from platform-level blocking

Two things set the CSE approach apart. It stops at the AI app rather than the platform behind it, and it reaches the AI answers built into Google Search.

Nothing outside the AI app is affected. Other products enforce this at the platform level, which means blocking the provider outright. Blocking non-corporate Google Gemini that way also blocks a user’s personal Gmail, because both live behind the same Google sign-in. Users lose access to services that have nothing to do with AI, and the help desk absorbs the complaints.

CSE enforces at the prompt instead. A user signed in with a personal account cannot submit prompts to a supported AI app, and every other thing they do on that platform keeps working, including personal Gmail, Google Drive, and Google Search itself. You get the control without taking away unrelated personal services.

AI answers in Google Search are covered. Enforcement blocks Google AI Overviews and Google AI Mode, which are the two surfaces where a user gets model output without ever opening an AI app. Platform-level controls generally miss these, because the only way to block them at the platform is to block Google Search for everyone.

Pre-requisites

  • SIA Advanced license for your org
  • CSE desktop app 4.6.0 or later on the devices you want to cover. The app is what notifies a user that a prompt was blocked, and what keeps the CSE Secure Web Gateway certificate current in the device’s certificate store.
  • An ITP policy assigned to the devices you want to cover
  • TLS decryption turned on in that ITP policy, via the Enable Advanced Configurations toggle. The Require approved accounts setting is hidden until TLS decryption is on, so turn it on first if you do not see the setting. See Manage Internet Threat Protection (ITP) Policies.
  • For the ChatGPT desktop app, the CSE Secure Web Gateway (SWG) certificate authority chain added to the app’s pin list through your mobile device management (MDM) system. See Certificate-pinned apps.

Configure Require approved accounts

1. In the Command Center, navigate to Internet Access > Internet Threat Protection, and then select the ITP policy you want to edit.

2. Confirm Enable Advanced Configurations is toggled on. This is the setting that turns on TLS decryption for advanced blocking and file analysis. If it is off, toggle it on and save before continuing.

3. In the policy’s blocking settings, below Domain and URL Blocking, toggle on Require approved accounts.

4. Under Approved email domains, enter each email domain your organization signs in with. Select the + beside the field to add another domain, or the - to remove one.

Note: Enter the domain of your company identity, not the domain of the AI app. If your users sign in as name@sonicwall.com, enter sonicwall.com.

5. Select Save.

Note: Enforcement does not reach a session that is already open. A user with a supported AI app already loaded may need to refresh the browser window, or quit and restart the AI company’s desktop app, before the policy takes effect for them. Take this into account when you test the setting, and when you tell users what to expect.

Certificate-pinned apps

Require approved accounts depends on TLS decryption, so CSE has to be able to inspect the connection to the AI app. Most apps allow this with no work from you. The ChatGPT desktop app is the one that does not, and it needs one action from an administrator before enforcement works on it.

What happens. When CSE inspects an HTTPS connection, it decrypts the connection at the Secure Web Gateway (SWG), inspects it, and re-encrypts it with a certificate issued by CSE’s own certificate authority (CA). The CSE desktop app installs the SWG CA chain into the device’s certificate store automatically, and browsers and most applications read that store, so they accept the re-issued certificate and keep working.

An app that pins certificates checks the certificate against a list built into the app, after the normal certificate checks have already passed. Adding the CSE certificate to the device does not satisfy that check. On those apps, an inspected connection does not fail open and go unenforced. It fails closed, and the app cannot reach its service at all until the CSE certificate is added to the list the app accepts.

What to do. Add the CSE SWG certificates to the ChatGPT pin list and deliver that exception to devices through your mobile device management (MDM) system. OpenAI documents this as Step 6 of Corporate network controls in ChatGPT Enterprise. Download the certificates from SWG CA Certificates for Certificate-Pinned Apps, which covers what the change requires.

Warning: Do this before you turn on Require approved accounts for users who run the ChatGPT desktop app. Without it, those users lose access to ChatGPT rather than being held to your approved domains. The change is only possible on a device enrolled in an MDM system, so an unmanaged device running the ChatGPT desktop app cannot be brought under enforcement at all.

What users experience

When a user submits a prompt from an account that does not match an approved domain, the prompt is blocked. This covers:

  • Prompts from a personal or free account on a supported app
  • Prompts submitted in a private or incognito browser window, where the user is signed in to nothing at all
  • Google AI Overviews and Google AI Mode results in Google Search

On a supported AI app, the user also gets an operating system notification telling them the prompt was blocked. The AI answers in Google Search are the exception. Those results are suppressed with no notification, so the user sees the answer missing and is not told why. See No notification for AI answers in Google Search.

Prompts from an approved company account are unaffected, as is the rest of the user’s access to those platforms.

Review blocked prompts in Events

Blocks from this setting are recorded under a new Internet Access event type, which the console writes as one word: SAASSecurity.

1. In the Command Center, navigate to Home > Events.

2. Select the Internet Access tab. The Private Access tab beside it carries the events for private resources, not internet traffic.

3. Select Add Filter, and then select Event Type.

4. Select the SAASSecurity checkbox. The other Internet Access event types are Compliance, Threat, Malware, and ITPStatus, and you can select more than one.

Each event records the user and device, the app, and a message describing the block. See Events Viewer.

Use this to confirm the policy is working after you enable it, and to find the users who still need a company account on an app before you widen the policy.

Limitations

The limitations below come from how the traffic, the app, or the surface works. You address each one with configuration you control, or you accept it. One exception is called out at the end of this section: Application Bypass, which SonicWall is fixing before the feature becomes generally available.

QUIC between Chrome and Google services

QUIC is a UDP-based transport protocol that Chrome uses to reach Google services. CSE cannot inspect QUIC traffic, so while QUIC is active it bypasses filtering, and approved account enforcement along with it.

To enforce approved accounts on Google Gemini and on the AI answers in Google Search, disable QUIC on the device, for example with the Chrome QuicAllowed policy set to disabled.

Apps that pin certificates

The ChatGPT desktop app pins certificates, so it needs the CSE SWG CA chain added to its pin list by an administrator before inspection works on it. This is a property of the app, not something CSE can change, and it is only possible on a device enrolled in an MDM system. See Certificate-pinned apps.

Apps reached over the Secure Private Access path

If a supported AI app is reachable over your Secure Private Access (SPA) path, its traffic is excluded from ITP policy evaluation and therefore from approved account enforcement.

This is existing ITP behavior by design rather than a new limitation. Traffic destined for private resources or routed through a Service Tunnel is always excluded from ITP evaluation; see Routing. The services delivered over the SPA path are listed under Secure Private Access in Cloud Secure Edge (CSE) Licenses, and include Service Tunnels, hosted websites, and hosted infrastructure.

If you have included a supported AI app in a Service Tunnel, remove it from that tunnel’s included domains or IP ranges to bring it back under ITP enforcement.

AI answers in Bing

Suppression of AI answers in Bing is not supported yet. Enforcement covers the AI answers built into Google Search, including AI Overviews and AI Mode, but the equivalent Bing surfaces are not blocked.

When enforcement suppresses Google AI Overviews or Google AI Mode, the user gets no operating system notification. The AI answer is simply absent from the search results page, and nothing on the page explains why.

Users who notice the change will ask about it, so tell them ahead of time that your organization enforces company sign-in on AI. A user who is not told may read the missing answer as a Google problem and open a ticket.

Repeated notifications on ChatGPT

On ChatGPT, the operating system notification may repeat while the blocked page stays open, rather than appearing once for the blocked prompt. A user who leaves the page open can collect several notifications for the same block. Closing the page or navigating away stops them.

Apps added to Application Bypass

Adding a supported AI app to Application Bypass on the ITP policy removes CSE visibility into that app, so approved account enforcement does not apply to it. This follows the existing bypass precedence: bypasses are evaluated before every block rule, and bypassed traffic does not appear in logging. See How ITP rules are processed.

This is the one limitation on this page that is going away, and you do not have to restructure your bypass list to work around it. Your Application Bypass entries are a deliberate configuration, and SonicWall’s assumption is that the bypass list you run today is the one you intend to keep. Approved account enforcement will apply to an app whether or not it is bypassed, and that change is planned before this feature becomes generally available.

Until then, enforcement and Application Bypass are mutually exclusive on the same app. If you need enforcement on an app during the preview, take that app out of Application Bypass. If the bypass entry is there for a reason you are not willing to give up, leave it in place and wait for the fix rather than changing a working configuration.

What’s next

Was this page helpful?