To respond to risky travel sign-ins, create a Microsoft Entra Conditional Access policy that targets the intended users and resources, uses sign-in risk as a condition, and requires multifactor authentication (MFA) for the risk levels your organization chooses. Exclude emergency access accounts, test the policy in report-only mode, and enforce it only after reviewing the results. This risk-based capability requires Microsoft Entra ID P2.
What Entra means by risky travel
Microsoft Entra ID Protection can identify atypical travel and unfamiliar sign-in properties as distinct risk detections. Those signals may contribute to a sign-in risk assessment; they are not a guarantee that every trip will be detected or proof that an account has been compromised. Microsoft describes sign-in risk as “the likelihood that an authentication request isn’t from the identity owner.” Microsoft Learn: What is risk
Microsoft says the atypical-travel algorithm attempts to filter false positives. Its simulation guidance notes that atypical travel is difficult to simulate and describes filtering cases such as travel from familiar devices and sign-ins through VPNs used by other people in the directory. Treat a travel-related signal as a reason to apply an appropriate control or investigate, not as a definitive verdict.
Before you create the policy
- Check licensing: Microsoft documents Entra ID P2 as required for risk-based Conditional Access. Entra Suite is also identified as providing full access to ID Protection features; verify your tenant’s current entitlement before rollout. Microsoft Entra ID Protection licensing
- Choose scope deliberately: Decide which users and resources should be covered. Microsoft’s example uses all users and all resources, but that scope should be checked against your organization’s access model.
- Protect emergency access: Identify and exclude emergency or break-glass accounts to reduce the risk of locking administrators out.
- Check MFA readiness: Confirm that affected users are registered and can complete the authentication method the policy will require. Microsoft warns that users who are not registered for MFA can be blocked during risky sessions. Sign-in risk-based multifactor authentication
Create a sign-in risk policy
- In the Microsoft Entra admin center, go to Entra ID > Conditional Access and create a policy. Use a name that states its audience and purpose, such as “Risky sign-ins – require MFA.” Conditional Access policy for sign-in risk
- Under Users, select the users or groups to cover and exclude emergency access accounts. Under Target resources, select the resources the policy should protect. Validate broad selections such as all users or all resources before applying them.
- Under Conditions > Sign-in risk, enable the condition and select the risk levels to address. Microsoft’s example selects medium and high. Use that as a starting point for evaluation, not as a universal threshold.
- Under Access controls > Grant, require MFA. Select an authentication strength suitable for your organization, and make sure affected users can satisfy it.
- Set Enable policy to Report-only, then create the policy. Microsoft recommends reviewing the effect before turning a policy on. Conditional Access policy for sign-in risk
- Review the policy’s impact and sign-in results. After you have validated the scope and expected behavior, change the policy from report-only to enabled if you are ready to enforce it.
Keep sign-in risk and user risk in separate Conditional Access policies. Microsoft’s risk-policy guidance advises against combining these conditions in one policy. Configure risk policies
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Understand the location controls
Named locations represent countries or regions, IP ranges, or both, and can be selected as network conditions in Conditional Access. They can provide context for known networks or support a separate policy that blocks access from a defined location. Microsoft’s deployment guidance also says trusted or known locations can improve the accuracy of ID Protection risk calculations. A named location does not independently determine whether a person’s travel between two places was physically possible. Conditional Access: Network assignment
If you need a location-based block, define the named location, target the users and resources that should be covered, select the location under the network condition, and choose the appropriate grant control. Test that policy in report-only mode and exclude emergency access accounts as appropriate. A location block and a sign-in-risk response answer different questions: one applies a rule to configured geography or IP ranges; the other responds to a risk assessment.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Do not confuse Entra risk with Defender for Cloud Apps impossible travel
Microsoft Defender for Cloud Apps has a separate impossible-travel anomaly detection. It looks for activity from two locations in less time than travel would permit and requires at least one connected app using app connectors. That is a Defender for Cloud Apps detection, not the Entra ID Protection sign-in-risk condition used by the Conditional Access policy above. Anomaly detection policies in Microsoft Defender for Cloud Apps
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose the control that matches the signal
| Control | Signal | Policy mechanism and response | Prerequisite |
|---|---|---|---|
| Entra ID Protection sign-in risk | Risk detections can include atypical travel and unfamiliar sign-in properties. | Use sign-in risk as a Conditional Access condition; configure the policy to require MFA or another appropriate grant control. | Microsoft Entra ID P2 for the documented risk-based Conditional Access capability. |
| Named-location condition | Configured countries or regions and IP ranges provide location or network context. | Use a Conditional Access network condition to control access, including blocking access from selected locations. | Define the named location and configure a Conditional Access policy. |
| Defender for Cloud Apps impossible travel | Activity in connected apps appears in two locations within too little time for travel. | Use Defender for Cloud Apps anomaly detection; it is separate from the Entra sign-in-risk policy. | At least one connected app using app connectors. |
Conditional Access makes decisions by combining signals and enforcing organizational policies; it does not turn a travel anomaly into certainty. Microsoft Learn: What is Conditional Access?
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

