Skip to content

We want to block sign-ins from risky countries

Geo-blocking in Conditional Access is a coarse but effective filter. It works best if you have a clear work area (NL, EU, plus travel). It is not security, it is noise reduction so the real attack stands out.

Try this first

  1. 1In Entra Named Locations create a Trusted set: NL, plus the countries where people actually work or regularly travel. Add fixed office IP ranges as Trusted IP.
  2. 2Build a Conditional Access policy Block sign-in from untrusted countries: all users (except break-glass), all cloud apps, condition Locations = Any location, exclude Trusted Named Locations, action Block.
  3. 3Run Report-only for two weeks first. Check sign-in logs for legitimate trips or VPNs and adjust the Trusted set.
  4. 4Add a separate policy for admin roles: only from Trusted Named Locations, even if travelling. Admins travel through VPN to the office.
  5. 5Add an exception for mobile apps using roaming data (Outlook mobile on a foreign carrier). Sometimes they sign in from an unexpected country via a carrier IP. That is not an attack, solve it through Trusted Devices instead of Trusted Locations.

When to bring us in

If you have freelancers or partners working from countries you do not trust, use a separate Conditional Access policy with stronger MFA (FIDO2) instead of a blanket block. Geo-blocking for that group usually creates more noise than it removes.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.