Not exactly sure how streamlined your security process is, but for some orgs it is a red tape roller coaster to even get one TCP port open.
Anyways, you could also block all traffic to ngrok servers just to ensure your Dev teams aren't skirting around your firewall.