impossible travel detection
Warsaw at 17:40. Singapore at 03:12. Same account. We call it.
Stolen credentials log in politely: the token is valid, the permissions are real, every single event is allowed. The one thing that does not fit is where it happened. 1Security resolves every action in your tenant - not only sign-ins - to a country, city and network, replays each user and device leg by leg, and calls the trip impossible when it could not have happened. On a standard license.
- 5network types behind every action - VPN, Tor, datacenter and Microsoft relay called out
- 400 kmwhere the model switches from ground travel to flight plus airport time - conservative on purpose
- 0third-party IP lookups - enrichment runs inside 1Security
The problem
The audit log knows where every action came from. It tells you in IP addresses.
Nobody reads a column of numbers, so the cheapest compromise signal there is goes unread.
One user on a phone burns through dozens of addresses a day. Ask a raw log where a document library went at 3 AM and you get an address - no city, no network owner, no idea whether this origin is normal for this person or brand new.
There is a second trap that trips up almost every tool: many Microsoft 365 actions legitimately carry a Microsoft datacenter address rather than the person who triggered them. Read naively, that produces hundreds of phantom "US datacenter logins" for people who never left the office - and buries the one foreign sign-in that matters.
Sign-in-based detection has a blind spot by design: a stolen token that never signs in again - it just keeps calling Graph - leaves no sign-in to detect. It does leave file activity, mailbox operations and shares, and each of those has a place.
Capabilities
Every action placed. Every trip judged.
A location is a stable place - country, city, network owner - and everything else is built on that.
One place, not two hundred IPs
Country + city + network (ASN): who owns the connection, not which address it borrowed today. Hundreds of rotating IPs collapse into one "Warsaw, Poland - home ISP" row you can reason about.
- 5 types
The network type is the story
Standard, VPN, Tor, datacenter, Microsoft. An employee opening a spreadsheet through Tor or a hosting provider is one of the strongest early signs of a stolen session - one filter chip, no rules to write.
Microsoft relay traffic, recognised
Microsoft's IPv4 and IPv6 ranges are recognised and labelled neutrally, and Microsoft's own real-country signal wins over the relay address. A file previewed from Poland reads as Poland even when the connection was a Microsoft server in the US.
Travel trails with verdicts
Every user and device carries a trail of everywhere it has been seen active, newest first. Each leg gets distance, time gap, implied speed and a verdict: plausible, improbable, impossible. VPN, datacenter and Microsoft egress is never a waypoint.
First-seen detection
The first time a user appears at a location is flagged and filterable in the activity log. No baseline period, no model to train - "this origin is new for this person" is computed from day one.
Offices and coverage on the same map
Mark your company locations and every row shows its distance to normal. The Conditional Access tab lays your declared policy over the origins actually observed, so declared trust and real traffic can disagree in public.
The verdict
No single event is suspicious. The trip is.
Every step an attacker takes with a valid token is technically permitted. The place is the part that does not fit.
An account authenticates in Warsaw at 17:40 and downloads a document library from Singapore at 03:12. The credential is real, the permissions are real, the actions are allowed. A tool that reads events one at a time sees nothing.
1Security reads the trip: two resolved places, 9,400 km, nine and a half hours, no flight that makes it - verdict: impossible travel. It lands on the leg in the user's trail, one click from the verdict to the exact events that earned it, and it can raise an instant alert.
In practice
A stolen session, spotted by geography.
What the location trail looks like on the night it matters.
- 01
03:12 - a first-seen origin
An account that lives in Warsaw appears in a new country, on a hosting provider's network. Two flags land at once: first time this user has been seen there, and the network type is datacenter, not a home ISP.
- 02
03:14 - the leg gets its verdict
The trail draws the leg from the last real origin to the new one: 9,400 km in under ten hours - impossible. Microsoft relay ranges were already excluded, so the verdict is about a person, not a server.
- 03
03:20 - from verdict to events
One click pivots from the place to the exact activity that came from it: 600 files downloaded, two shared, and the device fingerprint that carried the session.
- 04
03:31 - the account is contained
From the same screen: revoke sessions and disable the account as staged actions, logged in Actions. The morning shift reads a timeline, not a mystery.
The difference
What placing every action gives you.
These come from placing every audited action, not only sign-ins.
- The user's real country even when the connection ran through a Microsoft relay - "US datacenter" logins labelled for what they are
- The network owner behind every action - home ISP, mobile carrier, VPN, Tor, hosting provider
- A first-seen flag on every new user-location pair, filterable in the activity log
- Per-device travel trails, built from the data access each device performed
- Impossible-travel verdicts on legs, with VPN, datacenter and Microsoft egress excluded from the route
- Location and Infrastructure columns and filters on the full activity log, up to three years deep
- Conditional Access coverage verdicts computed from the addresses actually seen, on the same screen
- All of it on a standard license - no premium add-on required
Deployment
Private by construction.
Location enrichment runs inside 1Security - your IP data is never sent to a third-party lookup service. Connect with read-only consent and places appear the same day, resolved for every action the audit log has already recorded.
- Same dayfrom read-only consent to first places on the map
- 0third-party IP services see your logs - enrichment is local
- Business Basicthe only Microsoft license it takes
Use cases
Three questions geography answers first.
The takeover triage: an alert names an account. Before touching permissions or content, open its trail - if the last week is one city on a home ISP, breathe; if last night added a first-seen country on a datacenter network, you already know how the next hour goes.
The 3 AM download: a sensitive library was pulled overnight. One click answers whether it went to the user's usual city or somewhere the account has never been - and the relay handling means the answer is about the person, not about a relay server.
The token-theft pairing: a first-seen origin plus a shadow device on the same account in the same window is as close to "this token is not with its owner" as passive telemetry gets. Both halves live in this product, one click apart.
Conditional Access Monitoring
The Coverage tab compares the Conditional Access you declared with the origins you actually observe.
See the feature →Shadow Device Detection
The other half of the token-theft signal: the machine that never enrolled and never authenticated.
See the feature →Microsoft 365 Audit Tool
Up to three years of activity behind every place - the trail the verdict points into.
See the feature →
FAQ
Impossible travel detection, asked directly.
Do I need Entra ID P2 or Microsoft E5 for this?
No. Location intelligence works on a standard Microsoft 365 license - Business Basic is enough. No premium add-on required. Enrichment runs inside 1Security.
How is this different from Entra ID Protection's travel detections?
It complements them. Entra ID Protection reasons about sign-in events; 1Security resolves a place for every audited action - file activity, mailbox operations, sharing, sign-ins - so a stolen token that never signs in again still leaves a geographic trail, and the history behind it goes back up to three years.
Does my IP data leave my environment?
No. Enrichment runs inside 1Security - your addresses are never sent to a third-party lookup service. What is stored is the resolved place: country, city and network.
Will Microsoft datacenter traffic cause false alarms?
That is exactly what the relay handling is for. Many server-side actions carry a Microsoft datacenter address rather than the user's. 1Security recognises Microsoft's IPv4 and IPv6 ranges, labels that traffic neutrally, and prefers Microsoft's real-country signal over the relay address - while never assuming that foreign-looking activity is "just Microsoft".
Is VPN or datacenter traffic always treated as a threat?
No - it is classified, not judged. VPN, Tor and datacenter origins are labelled so you can filter and alert on them; marked offices add the context of where work is expected to happen. The impossible verdict is reserved for trips that genuinely could not have happened: city centroids, 400 km ground-travel allowance, flight plus airport time above that.
Ask where, before you ask what.
Connect read-only and see your tenant's real map the same day: every origin, every network type, every first-seen flag - and the trips that could not have happened.
Or keep translating IP addresses by hand, one incident at a time.