---
title: Locations
description: See every place your Microsoft 365 activity really comes from - offices, home networks, VPNs, Tor and datacenters - and whether your Conditional Access rules actually govern them.
icon: Globe
---

# Locations

The Locations screen answers two questions that belong together: **"Where is our data actually being reached from - and do the rules we declared match that reality?"** Every sign-in and every file action in your tenant happens somewhere; this screen collects those somewheres into stable, named places, ranks them by activity, and lays your Conditional Access configuration over the top so the gaps have nowhere to hide.

A **Location** here is not an IP address. It is a resolved identity made of country, city, and the network that owns the connection - so two hundred fleeting addresses from one household read as a single "Warsaw, Poland - home ISP" row. How that resolution works, including how Microsoft's own relay traffic is recognised and neutralised, is covered in [Location Intelligence](/en/docs/location).

## What You Can Achieve

<Cards>
  <Card
    title="Spot the origin that should not exist"
    description="A Tor exit, a commercial VPN, a hosting provider touching your files - each is one quick-filter chip away, with live counts. No rules to write, no baseline to train."
  />
  <Card
    title="Separate your offices from everything else"
    description="Mark the places that are really yours, give each a normal-use radius, and every other location shows its distance to the nearest office - so unusual egress stands out at a glance."
  />
  <Card
    title="Find the places no policy governs"
    description="The Conditional Access tab compares what you declared in Entra with the sign-ins actually observed - and counts the ones that completed with no policy in force at all."
  />
  <Card
    title="Turn a place into an investigation"
    description="Every location opens into a drawer with its activity trend, users, devices, logs, and its own Conditional Access story - one click from a suspicious row to the exact events."
  />
</Cards>

## Four Tabs, One Question

- **Locations** - every place activity has been observed from, as a filterable, sortable list.
- **Company locations** - the places you have marked as offices, plus recommended candidates.
- **Map** - the same data on a world map, with layers for offices, user locations, Microsoft datacenters, suspicious networks, and Conditional Access gaps.
- **Conditional Access** - your declared policy laid over observed reality. See [Conditional Access](/en/docs/conditional-access) for the full mechanics.

## Reading the List

By default the list bundles locations **by city**, because geo databases love answering with district and suburb names around every metro - the bundled view keeps one row per city, and clicking it drills into the individual locations behind it. Switch to **All locations** for the raw view.

Each row carries the location's identity - country, city, and **network** (the ASN: a home ISP, a mobile carrier, a corporate network, a cloud provider) - alongside its **infrastructure type**, its **CA coverage** verdict, the distance to the **nearest office**, how many **events**, **users** and **devices** have been seen there, an **activity sparkline**, and when it was **first** and **last seen**.

Above the list, quick-filter chips put the highest-signal cuts one click away, each with a live count: **Tor**, **VPN**, **Datacenter**, and **Microsoft**. The full filter drawer goes further - by country, city, network, infrastructure type, Conditional Access coverage state, a specific CA finding, or a specific named location.

<Callout type="info">
  A high-signal pattern that costs ten seconds: open the **Tor** and
  **Datacenter** chips, then sort by **first seen** descending. A brand-new
  anonymised origin that is already producing activity is one of the strongest
  compromise leads passive telemetry can give you.
</Callout>

**First seen** deserves special attention across this screen: 1Security flags the first time any user is observed at a given location, so "new place, real activity" is a filterable fact rather than a hunch.

## Company Locations

Offices are the anchor of the whole screen: once 1Security knows where normal work happens, everything else can be measured by its distance from normal.

Marking an office takes one click on any location row and a short dialog - name the office and set its **normal-use radius** in kilometres. From then on, every location row and map point shows how far it sits from the nearest office.

The tab opens with **Recommended actions** - candidates derived from what we observe, what Entra declares, and what you have already marked. A suggestion like _"This looks like an office"_ comes with its evidence attached: dozens of users behind a handful of addresses, weekday-and-working-hours concentration, managed devices, sustained activity across many days. Accepting a suggestion opens the ordinary marking dialog, so you stay in control of the name and radius. The reverse direction exists too: _"This office has gone quiet"_ flags marked offices with no recent activity.

## The Map

The Map tab draws every located place on a world map - point size follows activity, quiet locations fade, and clusters group nearby points until you zoom. Layers toggle **offices** (with their radius), **user locations**, **Microsoft datacenters**, **suspicious networks** (VPN, Tor and hosting egress), and **CA gaps** - a ring around every location Conditional Access does not cover, covers only partly, or has never enforced at. A time-range control from 24 hours to all-time turns the map into an answer for "where were we being reached from last week?"

## The Conditional Access Tab

This tab is the observed-versus-declared comparison in one place. The headline strip summarises your configuration - enforcing policies, report-only policies, named locations and how many are trusted - next to the number that matters most: the **share of sign-ins that completed with no policy applied**.

Every observed location carries one coverage verdict - **Not covered**, **Partly covered**, **Named**, **Trusted**, or **Undetermined** - computed from the source addresses actually seen there, not from the policy's stated scope. Findings explain why a row deserves action: sign-ins with **no enforcement**, **undeclared but active** places, an **office not trusted** by any trusted range, a **trusted range resolving to risky infrastructure**, a **range your egress has outgrown**, **country-only coverage**, and more - each with a live count of the locations carrying it.

The **Named locations** sub-view turns the comparison around and starts from what you declared: ranges nothing has ever signed in from, named locations no enabled policy references, and ranges Microsoft returned in a form that could not be parsed - shown rather than silently swallowed.

<Callout type="info">
  Two rows worth checking the day you connect this: a **trusted** named location
  whose traffic resolves to VPN or hosting infrastructure, and a trusted range
  that is **never seen**. Both are standing exceptions in every policy that
  excludes trusted locations - one is rented to strangers, the other has no
  owner at all.
</Callout>

Connecting the tab takes a single read-only re-consent (`Policy.Read.All`); the per-sign-in verdicts are already inside the logs 1Security ingests. Conditional Access itself requires **Microsoft Entra ID P1** on the Microsoft side - if your tenant does not have it, 1Security says so plainly, and everything else on this screen keeps working.

## Travel, Per User and Per Device

Locations follow the identities that visit them. Inside every user and device drawer, a **travel trail** replays that identity's movement between places - each leg with the distance covered, the time gap, the speed that gap implies, and a verdict: **plausible**, **improbable**, or **impossible travel**. A leg flagged as impossible ("1,800 km in 40 minutes") is a stronger statement than any anomaly score, and it links straight to the exact events on both ends.

<Callout type="info">
  Verdicts are deliberately conservative: positions are city centroids, never
  street-level, and the feasibility model allows ground travel below 400 km and
  a flight plus airport time above it. When a leg is still flagged, it is worth
  your attention.
</Callout>

## Licensing

Everything on this screen runs on a **standard Microsoft 365 license**. Location resolution happens locally - no third-party IP lookup service ever sees your data - and requires no Entra ID P2 or premium sign-in log add-on. The one exception is the Conditional Access tab's Microsoft-side prerequisite described above, and that limit belongs to Conditional Access itself, not to 1Security.
