On the server side, for example with Cloud Server (and then adding your node machines such as Enterprise Desktop or Workstation hosts) as your users’ single entry point, you disable direct access to node and configure the Cloud Server to allow specific access for specific users.
You can also use custom scripts which are run on the server upon a given event. I’m not sure what server product you are using, but all the guides in the documents section have a chapter about custom scripts (Server Automation Interface).
Alternatively, you could block specific client-side IP addresses on the corporate firewall and allow only those that you want to come through.