Restrict Google Workspace to your gateway IP

Google Workspace's IP control is Context-Aware Access: you define an access level (here: "coming from the Reach gateway IP") and assign it to apps, so Gmail, Drive, Meet and the rest only open for users who match. It's available on Enterprise Standard / Plus, Education Standard / Plus, Frontline Standard / Plus, Enterprise Essentials Plus and Cloud Identity Premium — not Business Starter/Standard/Plus.

1. Create the access level

  1. Admin console → Security → Access and data control → Context-Aware Access.
  2. Access levels → Create access level, name it TYO Reach gateway.
  3. Add a condition of type IP subnet with your gateway IP as 203.0.113.10/32 (one condition per region, joined with OR). Save.

2. Assign it to apps

  1. Context-Aware Access → Assign access levels.
  2. Pick the organisational unit or group, select the apps (Gmail, Drive and Docs, Calendar, Meet…), Assign, choose the TYO Reach gateway level and save.

Users in scope who aren't routed through Reach see a "you don't have access" message in those apps. Policy evaluation is continuous for Workspace core apps, so switching Reach off mid-session cuts access within minutes.

3. Route Google through Reach

Add google.com, googleapis.com, googleusercontent.com, gstatic.com and your Workspace domain's mail/drive hosts to your organisation's routing policy first, and test with one user before assigning the level broadly.

Limits worth knowing

  • Applies to end-user accounts only — service accounts and API calls with service-account credentials aren't restricted.
  • For third-party SAML apps the level is checked at sign-in only, not continuously, and browser-based sign-in on mobile is blocked when device policies are used.
  • Mobile users need the Reach Android/iOS app routing the Google domains, or they'll fail the IP condition.

Common questions

Business Plus and no Context-Aware Access — alternatives?

Enforce 2-Step Verification and use Google's login challenges; there's no IP gate below Enterprise. The gateway IP still helps for the other tools you allowlist.

Can I combine IP with device conditions?

Yes — an access level can require both an IP subnet and a managed/encrypted device. Start with IP only so Reach rollout and device enrolment aren't tangled.

Source: Protect your business with Context-Aware Access