How to Alert on Microsoft Entra Sign-Ins from Other Countries
Question details
The user needs to know how to configure alerts and restrictions for successful sign-in attempts originating from foreign or unexpected countries.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Securing organizational accounts and identifying compromised credentials after a phishing incident or anomalous activity.
- Observed behavior
- Administrators require a reliable method to monitor, report on, and automatically enforce secondary authentication or blocking for logins originating outside trusted geographical boundaries.
Ensure you have Conditional Access Administrator or Security Administrator privileges in your tenant, and verify your licensing tier, as certain risk-based features require a Microsoft Entra ID P2 license.
Configure Conditional Access with Named Locations
Create explicit geographical boundaries to block access or require multifactor authentication (MFA) when a user signs in from an untrusted country.
This method relies on defining specific countries or IP ranges as named locations. You can either create a list of 'trusted' locations and block everything else, or create a 'blocked' list of high-risk countries.
Sign in to the Microsoft Entra admin center. Navigate to Protection > Conditional Access > Named locations. Click 'Countries location', select the countries you want to restrict, and save the location.
Go to Protection > Conditional Access > Policies and click 'New policy'. Assign a name to the policy and select the users or groups it should apply to.
Under 'Conditions', select 'Locations'. Set 'Configure' to Yes, choose 'Include', and select 'Selected locations'. Pick the named location you created in the first step.
Under 'Access controls' > 'Grant', select either 'Block access' to completely prevent sign-ins, or 'Grant access' while checking 'Require multifactor authentication'.
Set the policy state to 'On' (or 'Report-only' if you want to test the impact first) and click 'Create'.

Monitor Anomalies using Identity Protection
Leverage machine learning to automatically flag and respond to 'atypical travel' or logins from unfamiliar locations.
Integrate Alerts with Microsoft Sentinel
Route Microsoft Entra ID logs to a SIEM tool like Microsoft Sentinel to create automated, real-time alerts for foreign sign-ins.
Enhance Your Productivity with WPS Office
While you secure your organization's infrastructure with Microsoft Entra ID, ensure your team has access to a reliable, lightweight, and cost-effective productivity suite. WPS Office is a powerful alternative that handles documents, spreadsheets, and presentations with ease.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install the Suite: Run the downloaded executable and follow the on-screen setup instructions.
- 3. Start Creating: Open WPS Office and seamlessly open your existing DOCX, XLSX, or PPTX files.

Frequently Asked Questions
Do I need a Microsoft Entra ID P2 license to block countries?
No. You can configure Named Locations and standard Conditional Access policies to block specific countries using a Microsoft Entra ID P1 license. However, automated risk-based policies (like atypical travel detection) require the P2 license.
Can I exempt certain users from a country-blocking policy?
Yes. When configuring a Conditional Access policy, you can select 'Exclude' under the Users or Groups section to exempt specific administrators, traveling executives, or break-glass accounts from the geographical restrictions.
How accurate is the location detection in Microsoft Entra ID?
Location detection is based on the IP address of the sign-in request. While generally accurate at the country level, the use of VPNs, proxies, or corporate routing can sometimes misrepresent a user's actual physical location.




