Locations
See every place your Microsoft 365 activity really comes from - offices, home networks, VPNs, Tor and datacenters - and whether your Conditional Access rules actually govern them.
Locations
The Locations screen answers two questions that belong together: "Where is our data actually being reached from - and do the rules we declared match that reality?" Every sign-in and every file action in your tenant happens somewhere; this screen collects those somewheres into stable, named places, ranks them by activity, and lays your Conditional Access configuration over the top so the gaps have nowhere to hide.
A Location here is not an IP address. It is a resolved identity made of country, city, and the network that owns the connection - so two hundred fleeting addresses from one household read as a single "Warsaw, Poland - home ISP" row. How that resolution works, including how Microsoft's own relay traffic is recognised and neutralised, is covered in Location Intelligence.
What You Can Achieve
Spot the origin that should not exist
A Tor exit, a commercial VPN, a hosting provider touching your files - each is one quick-filter chip away, with live counts. No rules to write, no baseline to train.
Separate your offices from everything else
Mark the places that are really yours, give each a normal-use radius, and every other location shows its distance to the nearest office - so unusual egress stands out at a glance.
Find the places no policy governs
The Conditional Access tab compares what you declared in Entra with the sign-ins actually observed - and counts the ones that completed with no policy in force at all.
Turn a place into an investigation
Every location opens into a drawer with its activity trend, users, devices, logs, and its own Conditional Access story - one click from a suspicious row to the exact events.
Four Tabs, One Question
- Locations - every place activity has been observed from, as a filterable, sortable list.
- Company locations - the places you have marked as offices, plus recommended candidates.
- Map - the same data on a world map, with layers for offices, user locations, Microsoft datacenters, suspicious networks, and Conditional Access gaps.
- Conditional Access - your declared policy laid over observed reality. See Conditional Access for the full mechanics.
Reading the List
By default the list bundles locations by city, because geo databases love answering with district and suburb names around every metro - the bundled view keeps one row per city, and clicking it drills into the individual locations behind it. Switch to All locations for the raw view.
Each row carries the location's identity - country, city, and network (the ASN: a home ISP, a mobile carrier, a corporate network, a cloud provider) - alongside its infrastructure type, its CA coverage verdict, the distance to the nearest office, how many events, users and devices have been seen there, an activity sparkline, and when it was first and last seen.
Above the list, quick-filter chips put the highest-signal cuts one click away, each with a live count: Tor, VPN, Datacenter, and Microsoft. The full filter drawer goes further - by country, city, network, infrastructure type, Conditional Access coverage state, a specific CA finding, or a specific named location.
A high-signal pattern that costs ten seconds: open the Tor and Datacenter chips, then sort by first seen descending. A brand-new anonymised origin that is already producing activity is one of the strongest compromise leads passive telemetry can give you.
First seen deserves special attention across this screen: 1Security flags the first time any user is observed at a given location, so "new place, real activity" is a filterable fact rather than a hunch.
Company Locations
Offices are the anchor of the whole screen: once 1Security knows where normal work happens, everything else can be measured by its distance from normal.
Marking an office takes one click on any location row and a short dialog - name the office and set its normal-use radius in kilometres. From then on, every location row and map point shows how far it sits from the nearest office.
The tab opens with Recommended actions - candidates derived from what we observe, what Entra declares, and what you have already marked. A suggestion like "This looks like an office" comes with its evidence attached: dozens of users behind a handful of addresses, weekday-and-working-hours concentration, managed devices, sustained activity across many days. Accepting a suggestion opens the ordinary marking dialog, so you stay in control of the name and radius. The reverse direction exists too: "This office has gone quiet" flags marked offices with no recent activity.
The Map
The Map tab draws every located place on a world map - point size follows activity, quiet locations fade, and clusters group nearby points until you zoom. Layers toggle offices (with their radius), user locations, Microsoft datacenters, suspicious networks (VPN, Tor and hosting egress), and CA gaps - a ring around every location Conditional Access does not cover, covers only partly, or has never enforced at. A time-range control from 24 hours to all-time turns the map into an answer for "where were we being reached from last week?"
The Conditional Access Tab
This tab is the observed-versus-declared comparison in one place. The headline strip summarises your configuration - enforcing policies, report-only policies, named locations and how many are trusted - next to the number that matters most: the share of sign-ins that completed with no policy applied.
Every observed location carries one coverage verdict - Not covered, Partly covered, Named, Trusted, or Undetermined - computed from the source addresses actually seen there, not from the policy's stated scope. Findings explain why a row deserves action: sign-ins with no enforcement, undeclared but active places, an office not trusted by any trusted range, a trusted range resolving to risky infrastructure, a range your egress has outgrown, country-only coverage, and more - each with a live count of the locations carrying it.
The Named locations sub-view turns the comparison around and starts from what you declared: ranges nothing has ever signed in from, named locations no enabled policy references, and ranges Microsoft returned in a form that could not be parsed - shown rather than silently swallowed.
Two rows worth checking the day you connect this: a trusted named location whose traffic resolves to VPN or hosting infrastructure, and a trusted range that is never seen. Both are standing exceptions in every policy that excludes trusted locations - one is rented to strangers, the other has no owner at all.
Connecting the tab takes a single read-only re-consent (Policy.Read.All); the per-sign-in verdicts are already inside the logs 1Security ingests. Conditional Access itself requires Microsoft Entra ID P1 on the Microsoft side - if your tenant does not have it, 1Security says so plainly, and everything else on this screen keeps working.
Travel, Per User and Per Device
Locations follow the identities that visit them. Inside every user and device drawer, a travel trail replays that identity's movement between places - each leg with the distance covered, the time gap, the speed that gap implies, and a verdict: plausible, improbable, or impossible travel. A leg flagged as impossible ("1,800 km in 40 minutes") is a stronger statement than any anomaly score, and it links straight to the exact events on both ends.
Verdicts are deliberately conservative: positions are city centroids, never street-level, and the feasibility model allows ground travel below 400 km and a flight plus airport time above it. When a leg is still flagged, it is worth your attention.
Licensing
Everything on this screen runs on a standard Microsoft 365 license. Location resolution happens locally - no third-party IP lookup service ever sees your data - and requires no Entra ID P2 or premium sign-in log add-on. The one exception is the Conditional Access tab's Microsoft-side prerequisite described above, and that limit belongs to Conditional Access itself, not to 1Security.
Devices
See every device touching your data - including the ones Microsoft never told you about - and answer whether your information is being accessed from machines you don't control.
Agents
Govern every AI agent in your tenant - what each can actually read across files, sites, users, and email, who deployed it, and how to constrain it before rollout.