entra id named locations vs trusted ips: migration steps
Migration steps from legacy trusted IPs to named locations in Entra ID: inventory, recreate as named locations, update policies, test. Use when Conditional Access still references the old trusted-IPs list. Not for building location policy from scratch.
TL;DR
Named locations replaced the old trusted-IPs list in Conditional Access. Migration means inventorying the current trusted IPs, recreating each as a named location marked trusted where appropriate, updating every Conditional Access policy to reference the named location, and only then removing the legacy list.
The query
entra id named locations vs trusted ips: migration stepsUse this when
- Conditional Access policies still using the legacy trusted IPs setting
- adding a new office range to the trusted set
- auditing which policies depend on location trust
Not for
- designing location-based policy from nothing (start with named locations directly)
- IPv6 ranges your apps do not see (verify what the apps log)
- skipping the test step on a Friday afternoon
Steps
- Document every IP range in the trusted IPs list and what each range is for. Expected output: a complete inventory with owners
- In Entra admin center, create a named location for each range, marking corporate ranges as trusted. Expected output: named locations mirror the old list
- Open each Conditional Access policy that references trusted IPs and switch the location condition to the matching named location. Expected output: no policy still uses the legacy setting
- Test with one user on the corporate network and one off it. Expected output: corporate users get the trusted experience and others do not
- Remove the legacy trusted IPs list once migration is confirmed. Expected output: named locations are the single source of truth
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_66DU9Sx86QZMgJvMZJtnEQ