Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Named locations and risk-based Conditional Access solve different problems, so most organizations should use them together. A named location describes where a sign-in appears to come from; sign-in risk estimates whether that particular authentication may be unauthorized. Use location rules for network or geographic boundaries, and risk policies to challenge or block suspicious sign-ins. For legitimate travel into a blocked country, use a controlled, reviewable exception rather than disabling the location policy broadly.

Named locations and sign-in risk are different signals

A named location is a network or geographic condition: it can represent public IPv4 or IPv6 ranges, countries or regions, areas Entra cannot map to a country, or a Global Secure Access compliant network. Conditional Access can include or exclude selected locations. A trusted IP location can also help improve ID Protection’s risk calculations. Microsoft’s network assignment guidance describes these location conditions.

Sign-in risk is an assessment of the likelihood that an authentication request did not come from the identity owner. ID Protection evaluates signals and makes risk available to Conditional Access, which can allow access, require MFA or reauthentication, or block. User risk is different: it concerns the likelihood that the identity itself is compromised, rather than the assessment of one sign-in. See Microsoft’s ID Protection risk policy documentation.

Decision Named locations Risk-based Conditional Access
What it evaluates Public IP or network, geography, or compliant-network membership. Microsoft Learn ID Protection’s sign-in or user risk signals. Microsoft Learn
Best fit Enforcing known network boundaries, excluding disallowed countries, or applying different requirements on and off trusted networks. Responding to suspicious sign-ins with an adaptive challenge, reauthentication, or block.
Travel effect A traveler can be blocked simply because the observed origin changed. A controlled exception may be appropriate for an authorized trip. Travel is context to investigate alongside other detections; a risk condition can trigger the configured response.
Operational dependency Accurate IP ranges and country choices, including how Entra maps IPs and handles unknown areas. Availability of ID Protection risk signals; the cited sign-in-risk MFA policy requires Entra ID P2.
Common failure A bad scope or overbroad exception can block legitimate access or weaken the boundary. A detection may be a false positive or may be surfaced after sign-in; investigate and calibrate the policy.

Should you block sign-ins by country or use sign-in risk?

Choose by the question the policy needs to answer. A country or network rule asks, “Is this origin allowed?” A risk rule asks, “Does this authentication look like it may be unauthorized?” Blocking countries where the organization does not operate can enforce a straightforward boundary. Requiring MFA when a user is off the corporate network is another location-based use. However, location-based block policies are enforced after first-factor authentication, so they are not a pre-authentication defense. Microsoft’s location block policy guidance explains the control and recommends testing it before enforcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Risk-based policies are better suited to responding to suspicious activity rather than treating every sign-in from a particular country as equally suspicious. They do not replace investigation: a sign-in flagged during travel can be legitimate, and a familiar location alone does not establish that a sign-in is safe. Using both signals lets the organization maintain a geographic or network boundary while applying a separate response to risky events.

How to let users sign in while traveling

If a legitimate business trip would otherwise fall inside a blocked-country policy, Microsoft documents managing exclusions as a use case. A practical pattern is a dedicated cloud security group for travelers, with self-service group management where appropriate. Make membership time-bounded or otherwise regularly reviewed, and follow the organization’s approval and access-review practices; do not convert a trip exception into a permanent, broad bypass. See Microsoft’s guidance on users excluded from Conditional Access policies.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Confirm the policy scope. Identify the location condition and users affected, then verify that the planned destination is actually covered by the block.
  2. Use a controlled exception. Add only approved travelers to the designated exclusion group, and limit or review membership according to organizational practice.
  3. Keep other controls active. An exclusion from a location policy should not silently remove the user from unrelated Conditional Access or risk policies.
  4. Validate before enforcement. Use report-only mode and policy impact or What If validation for restrictive changes. Protect emergency access accounts from accidental lockout, following Microsoft’s location policy guidance.

How to investigate an atypical-travel alert

An atypical-travel detection is a reason to check the sign-in, not by itself proof of compromise. Microsoft’s investigation guidance recommends checking whether the user traveled to the reported destination and whether the IP is known for the user’s duties. Also check whether the address range belongs to a sanctioned VPN. If you confirm that it does, Microsoft advises adding the range to named locations; if the activity is not legitimate, mark the sign-in compromised and invoke remediation. Follow Microsoft’s ID Protection investigation guidance.

  • Confirm the user’s actual travel and expected work location.
  • Check the reported IP against known business use and sanctioned VPN records.
  • Review the sign-in and related risk detections in context rather than treating geography alone as a verdict.
  • If confirmed illegitimate, mark the sign-in compromised and take the recommended remediation steps.

Example: a risk-based MFA policy

Microsoft’s documented sign-in risk-based MFA example requires Microsoft Entra ID P2. It selects medium and high sign-in risk, requires MFA, and sets sign-in frequency to Every time. Microsoft presents those thresholds as a recommendation that may not suit every organization. Users must already have a registered authentication method capable of satisfying MFA. The configuration is described in Microsoft’s sign-in risk-based MFA instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check legacy risk policies and policy timing

Microsoft states that legacy ID Protection sign-in and user risk policies are retiring on October 1, 2026, and recommends migration to Conditional Access. As of October 4, 2026, check whether the tenant still has legacy policies, their status, and whether Conditional Access replacement policies cover the intended scenarios. Microsoft’s ID Protection risk policy documentation describes the retirement.

A location change may not affect every app immediately. For modern-authentication mobile and desktop apps, location is evaluated during token acquisition or refresh, typically once an hour by default. Web policy checks occur at initial sign-in and when a new sign-in token is requested; session behavior varies by app. Users who switch networks mid-session may therefore not see a location-policy change applied at once. See Microsoft’s network assignment documentation.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.