## TL;DR
Named locations replaced the old trusted-IPs list in Conditional Access. Migration means inventorying the current trusted IPs, recreating each as a named location marked trusted where appropriate, updating every Conditional Access policy to reference the named location, and only then removing the legacy list.

## The query
```text
entra id named locations vs trusted ips: migration steps
```

## Use this when
- Conditional Access policies still using the legacy trusted IPs setting
- adding a new office range to the trusted set
- auditing which policies depend on location trust

## Not for
- designing location-based policy from nothing (start with named locations directly)
- IPv6 ranges your apps do not see (verify what the apps log)
- skipping the test step on a Friday afternoon

## Steps
1. Document every IP range in the trusted IPs list and what each range is for. Expected output: a complete inventory with owners
2. In Entra admin center, create a named location for each range, marking corporate ranges as trusted. Expected output: named locations mirror the old list
3. Open each Conditional Access policy that references trusted IPs and switch the location condition to the matching named location. Expected output: no policy still uses the legacy setting
4. Test with one user on the corporate network and one off it. Expected output: corporate users get the trusted experience and others do not
5. Remove the legacy trusted IPs list once migration is confirmed. Expected output: named locations are the single source of truth

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_66DU9Sx86QZMgJvMZJtnEQ
