Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can screen for impossible travel with sign-in logs most organizations already collect. Group successful sign-ins by user, sort them by time, and flag consecutive pairs whose locations are too far apart to cover in the time between them. The result is a lead for investigation, not a verdict. It does not reproduce a commercial UEBA model, and a geographic flag by itself cannot show that credentials were stolen.

What impossible travel means, and how it differs from atypical travel

Impossible travel is a time-and-location anomaly. Two sign-ins for the same account come from places far enough apart that a person could not physically travel between them in the elapsed time. Microsoft documents this as a specific identity risk detection in Microsoft Entra ID Protection.

Atypical travel is a different detection. It also asks whether a location is unusual for that particular user. Entra ID Protection learns a new user’s sign-in patterns during an initial period that ends at the earlier of 14 days or 10 logins. Impossible travel is a test on a pair of events, so a custom rule built on the same idea does not need that per-user history to run.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Aspect Impossible travel Atypical travel
What it tests Whether two sign-ins are too far apart to be physically reachable in the time between them Whether a sign-in location is unusual for this user’s history
Per-user baseline Not described as a learned baseline in Microsoft’s documentation Yes. Learns during the earlier of 14 days or 10 logins
Calculation Offline detection, sourced from Microsoft Defender for Cloud Apps information Offline detection
Documented Microsoft licensing Entra ID P2 plus standalone Defender for Cloud Apps, or Microsoft 365 E5 with Enterprise Mobility + Security E5 Microsoft Entra ID P2

These licensing notes reflect Microsoft’s Entra ID Protection documentation as of October 2026. Product packaging changes, so confirm your tenant’s entitlements in current Microsoft licensing documentation before you depend on a built-in detection.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to detect impossible travel from logs you already have

A custom workflow needs only a handful of fields per sign-in event:

  • A stable user identifier, such as the directory object ID. Display names and mailbox aliases change and can split one person into several accounts.
  • A UTC timestamp with sub-second precision if your platform records it.
  • The result status, so you correlate successful authentications only.
  • The source IP address, plus country, city, and coordinates from your geo-IP lookup.
  • The application or resource name, the client or user-agent string, and a device identifier where the log provides one.

Correlation steps

  1. Export successful sign-in events. In the Microsoft Entra admin center, sign-in logs are under Monitoring & health > Sign-in logs. For retention and querying beyond the portal, route them to your log platform through Diagnostic settings.
  2. Normalize the fields listed above into one schema, so that a Conditional Access sign-in and a legacy protocol sign-in can be compared.
  3. Group events by user identifier and sort each group by timestamp.
  4. Resolve each IP address to coordinates using the same geo-IP source for every event.
  5. For each pair of consecutive events, compute the great-circle distance between the two locations and the elapsed time in hours. Divide distance by time to get the implied speed.
  6. Flag the pair when the implied speed exceeds a ceiling your team chooses. A common starting point is commercial airliner cruise speed, roughly 900 km/h, but the ceiling is a local parameter. Tune it against your own sign-in data and document why you chose it. It is not a validated industry standard.
  7. Send flagged pairs to triage with the context attached. Do not open automatic incidents for every flag.

Worked example

A user signs in at 09:00 UTC from an IP address geolocated to London, then at 11:00 UTC from one geolocated to Singapore. London to Singapore is roughly 10,800 km along a great circle. Over two hours that implies about 5,400 km/h, far above any reasonable ceiling, so the pair is flagged. Now compare a London sign-in followed by a Paris sign-in two hours later. Those cities are about 340 km apart, an implied speed of roughly 170 km/h, which passes the same check. The second pair is not flagged, even though a stricter rule might still review it for other reasons.

Illustrative logic

Field names differ between platforms, so treat this as a description of the logic rather than a tested rule:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
for each user_id:
  events = successful sign-ins for user_id, sorted by utc_time
  for prev, curr in consecutive_pairs(events):
    km    = haversine_km(prev.lat, prev.lon, curr.lat, curr.lon)
    hours = (curr.utc_time - prev.utc_time) / 3600
    if hours <= 0 and km > 0:
        flag_for_triage(prev, curr)    # simultaneous distinct locations need review too
    elif hours > 0 and km / hours > MAX_KMH:
        flag_for_triage(prev, curr)

Zero or negative time gaps need their own handling. Two different locations with the same timestamp, or a timestamp recorded in local time instead of UTC, can produce false flags or hide real ones.

Why VPN users trigger impossible-travel alerts

An IP geolocation is a proxy for where a device’s traffic appears to exit, not a measurement of where a person is. Several common situations make distant logins look legitimate or suspicious for the wrong reason:

  • A corporate or consumer VPN exit node in a different country from the user. The sign-in appears to come from the exit location.
  • A shared egress point, such as a cloud NAT, proxy, or large office gateway, that many users share. This can make one user appear to move, or make unrelated users look like they share one place.
  • Mobile carrier or roaming routes that geolocate to a distant gateway.
  • Geo-IP database errors, especially for recently allocated address ranges.
  • Real travel recorded with a timestamp error, which breaks the time calculation.

Microsoft’s security operations guidance for Entra user accounts states that “VPNs can cause false positives,” and recommends monitoring sign-in logs and IP address changes. That guidance is the reason to tune for VPNs rather than ignore them.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Tune with allowlists and context, not blanket suppression

  • Maintain an inventory of sanctioned VPN egress ranges. Tag sign-ins from those ranges so triage sees the context, and exclude them from the flag only where the range is documented and owned by you.
  • Where you have it, record known business travel from a travel or HR calendar, with an expiry date on each record.
  • Do not suppress every VPN or every distant location automatically. A compromised account can also sign in through a VPN, and blanket exclusions remove the signal you need most.
  • Recheck allowlists when a provider changes its egress addresses. Stale ranges quietly reintroduce false positives or hide real ones.

Triage: what to check before deciding

For each flagged pair, confirm first that both events belong to the same user, then compare the timestamps, IP addresses, locations, applications, devices, and user-agent details. Then check:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Whether the user was traveling, or whether a sanctioned VPN or a documented organization-wide network location explains the origin.
  • The user’s sign-in and risk history for other unusual characteristics, and whether the same account generated other alerts in the same window.
  • Surrounding events in the same session period, such as MFA prompts, password resets, new device registrations, mailbox rule changes, or access to sensitive applications.

If the sign-in is legitimate

Record the benign explanation, the evidence used (travel record, VPN range, or network owner), and the reviewer. Tune the known infrastructure narrowly, for example to a specific egress range rather than an entire provider. Where the platform offers a mark-as-safe action for a risky sign-in, use it so the decision is visible in the risk history.

If the activity is unauthorized

Follow your incident response process. Microsoft’s Entra risk investigation guidance describes marking a confirmed malicious sign-in as compromised, then resetting credentials, revoking active sessions, and blocking access where warranted. Review what the account accessed during the suspicious session before closing the case.

Rank #4
Fluke Networks 10660001 Security Key Insert for Can Wrenches
  • Reversible insert tool for can wrenches.
  • One end for SLC Cabinets. Other end for pin in head screws found in most Network Interface boxes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Custom correlation versus built-in identity risk detection

The two approaches answer overlapping questions with different inputs and different amounts of work. The comparison below uses only what Microsoft’s documentation states; where it is silent, the cell says so.

Axis Custom correlation on your logs Microsoft built-in identity risk detection
Required log sources Any identity log export you can normalize. You define the schema and coverage. Microsoft Entra sign-in data. Impossible travel also draws on Defender for Cloud Apps information.
Per-user baseline Pair-based only, unless you build a baseline yourself. Atypical travel learns per user over the earlier of 14 days or 10 logins. Impossible travel is documented as offline and pair-based detection.
VPN and shared egress handling Only what you encode, such as sanctioned-range allowlists and context tags. Microsoft documents that VPNs can cause false positives. Specific tuning controls are not stated in the documentation cited here.
Tuning and analyst burden You own the ceiling, schema, geo-IP source, allowlists, and testing against your own data. Vendor-managed detection logic. Customer-adjustable settings are not stated in the documentation cited here.
Licensing and retention Depends on your log platform’s ingestion and retention terms. Not established here. Entra ID P2, or Defender for Cloud Apps and Entra ID P2, or Microsoft 365 E5 with EMS E5, as documented. Retention terms not stated here.
Response actions Whatever your incident process and tooling support. Mark sign-ins safe or compromised, plus the response options Microsoft documents in risk investigation guidance.

Microsoft Sentinel documents UEBA anomalies for certain VPN products and log sources. These compare IP address, country or region, ISP, and user or organization patterns. They are UEBA features in that product, not evidence that every log platform supplies equivalent behavior. Microsoft’s security operations guidance also mentions Sigma rules as an evolving open standard, but it does not provide a complete portable impossible-travel rule. You will need to write and tune that logic against your own schema.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No accuracy rate, detection rate, or cost comparison between the two approaches is established in Microsoft’s documentation, so do not present one to stakeholders.

Choosing between the two

  • Use custom correlation when you already export identity logs, need coverage across identity sources beyond one vendor, and have analysts who can own thresholds, allowlists, and testing.
  • Use the built-in detections when your tenant already holds the licenses Microsoft documents, and you want the vendor to maintain the detection logic and feed it into the risk workflow.
  • Run both where licensing allows. A custom pair check can catch cases that a vendor’s detection scope does not cover, while the built-in signal gives you context you cannot easily reproduce from raw logs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.