Office 365 sign-in locations
Your sign-in log has 40,000 IP addresses. Your company works from 12 places.
A typical tenant produces tens of thousands of distinct IP addresses a month and works from a handful of cities. 1Security turns every Office 365 sign-in and file action into a place - country, city and the network behind it - marks your offices, flags VPN, Tor and hosting traffic, and lays your Conditional Access policy over what actually happens. On a standard license.
- 3 partscountry, city and network - one home ISP with 200 rotating addresses is one row
- 5network types behind every action: standard, VPN, Tor, datacenter, Microsoft
- 0third-party IP lookups - resolution runs inside 1Security, on a standard license
The problem
An IP address is not a place. An investigation needs places.
A log line answers "which address". An investigation needs "which place, which network, and is that normal for this person".
One employee on a phone burns through dozens of addresses a day; a mobile carrier hands hundreds to one office. Read at address level, a quiet week looks like a wall of noise, which is why address-level review is something teams try once and then stop doing.
There is a second trap: many Microsoft 365 events - server-side mailbox operations, background SharePoint actions, Copilot calls - legitimately carry a Microsoft datacenter address rather than the user's. Read naively, that raises "sign-in from a US datacenter" on people who never left the office, and after two false alarms nobody reads the third.
Conditional Access is written against named locations someone typed in once. Whether those ranges still match where sign-ins come from today is a question that needs your real traffic laid over your declarations. It is common to find a trusted named location that resolves to a VPN provider.
What you get
Every place your tenant is reached from, on one screen
Four tabs - Locations, Company locations, Map, Conditional Access - and every row one click from the sign-ins and file actions behind it.
One row per place
Country + city + network (ASN). Rows bundle by city by default because geo databases answer with suburb names; switch to All locations for the raw view. Filter by country, network type and first seen.
Network type on every row
Standard, VPN, Tor, datacenter or Microsoft. Four one-click chips with live counts - Tor, VPN, datacenter, Microsoft - so "who is opening files through a hosting provider" is a filter, not a script.
Offices as the anchor
Mark a location as an office in one click, set a normal-use radius, and every other row shows its distance to the nearest office. Recommended candidates arrive with evidence: dozens of users behind a few addresses, weekday hours, managed devices.
Conditional Access coverage
Each observed location carries a verdict - not covered, partly covered, named, trusted, undetermined - computed from the addresses actually seen there, plus the share of sign-ins that completed with no policy applied at all.
A map with layers
Offices with their radius, user locations, Microsoft datacenters, suspicious networks and a ring around every location Conditional Access does not cover. Point size follows activity; clusters open on zoom.
Travel per user and device
Every user and device drawer replays movement between places, leg by leg: distance, time gap, implied speed, and a plausible, improbable or impossible verdict with the events at both ends one click away.
How deep it goes
Two filters worth running the day you connect
The list is built so the compromise leads float to the top without writing a rule.
Open the Tor and datacenter chips and sort by first seen descending. A brand-new anonymised origin that is already producing file activity is one of the strongest signs of a stolen session passive telemetry can give you. In a typical mid-size tenant that list has a handful of rows, and each one deserves five minutes.
On the Conditional Access tab, read the headline number first: the share of sign-ins that completed with no policy applied. Most teams have never seen that figure for their own tenant, and it is rarely zero. Then the two rows that always turn up: a trusted named location whose traffic resolves to VPN or hosting infrastructure - a standing exception rented to strangers - and a declared range nothing has ever signed in from.
Once your offices are marked, sort by distance to the nearest office. Ordinary remote work sits within a few hundred kilometres on home ISPs and mobile carriers. A location 6,000 km out, on a hosting network, with three users this week is a row you open, not a judgement call.
In practice
From a suspicious row to the events behind it
The four clicks an investigation usually takes on this screen.
- 01
Mark your offices
Accept the recommended candidates or mark a row by hand and set its radius. From then on every location has a distance to normal.
- 02
Filter to what should not be there
Tor + datacenter chips, first seen this week, or distance over 1,000 km. Typical result: 3-15 rows in a tenant of a few thousand users.
- 03
Open the place
The location drawer shows its activity trend by action, its hourly pattern, users, devices, logs and its own Conditional Access verdict - "who was here and what did they do" on one screen.
- 04
Follow the identity
Jump to the user or device. The travel trail says "Warsaw 17:40, Singapore 03:12 - impossible" and links to the events at both ends. Stage a session revoke or account disable from the same screen, behind the review window.
The difference
What we build on top of the sign-in log
The same signals Microsoft records, assembled into places and compared with your policy.
- Locations as places (country + city + network) instead of lists of IP addresses
- File, mailbox and sharing actions located too - not only sign-ins
- Microsoft relay traffic recognised and labelled, so "US datacenter" alarms on office workers stop
- The share of sign-ins that completed with no Conditional Access policy applied
- A coverage verdict per observed location, from addresses actually seen there
- Trusted named locations that resolve to VPN or hosting providers, and declared ranges nobody signs in from
- Distance to the nearest office on every row and map point
- Per-user and per-device travel trails with impossible-travel verdicts, up to three years back
Licensing
Standard license, local resolution
Everything on this screen runs on a standard Microsoft 365 license, and location resolution happens inside 1Security - no third-party IP lookup service ever sees your addresses. Locations appear the same day you connect, resolved for the activity the audit log already recorded. The only Microsoft-side prerequisite belongs to Conditional Access itself.
- 1read-only re-consent (Policy.Read.All) connects the Conditional Access tab
- Entra ID P1the Microsoft-side requirement for Conditional Access; everything else works without it
- 400 kmwhere the travel model switches from ground travel to flight plus airport time
Related
Where this fits
A location, a device and an audit event are three views of the same sign-in. An investigation that starts on any of them usually finishes on the other two.
Conditional Access monitoring
Declared versus observed in full: coverage verdicts, unenforced sign-ins and the risk findings behind them.
See Conditional Access →Impossible travel detection
Visits and legs with plausible, improbable and impossible verdicts - and why conservative beats sensitive.
See travel →Unified audit log
The sign-ins and file actions behind every location row, retained up to three years.
See audit logs →
FAQ
Questions teams ask first
Why bundle locations by city?
Geo databases answer with district and suburb names around every metro, which splits one office into a dozen rows. The bundled view keeps one row per city and opens the individual locations on click; All locations is the raw view.
How do you avoid false alarms on Microsoft datacenters?
Many Microsoft 365 events carry a Microsoft datacenter address instead of the user's. 1Security recognises Microsoft's IPv4 and IPv6 ranges, labels that traffic as Microsoft, and prefers Microsoft's real-country signal over the relay address - while never assuming that a foreign sign-in is "just Microsoft".
Do I need Entra ID P2 or a premium sign-in log add-on?
No. Location resolution and everything built on it run on a standard license, Business Basic included. Conditional Access itself needs Entra ID P1 on the Microsoft side; without it the tab says so and the rest of the screen keeps working.
Does any third party see our IP data?
No. Resolution runs inside 1Security, not through an external lookup service. What is stored is the resolved place: country, city and network.
How conservative are the travel verdicts?
Deliberately. Positions are city centroids, not street level; the model allows ground travel below 400 km and a flight plus airport time above it; VPN, datacenter and Microsoft egress is never a waypoint. When a leg is still called impossible, it is worth your attention.
See the 12 places your tenant is really reached from - and the 13th.
Connect read-only and your locations resolve from activity you already generate, the same day. One extra read-only scope adds the Conditional Access tab.
Or keep reading IP addresses one at a time.