how to investigate impossible travel alerts with entra sign-in logs
How to investigate impossible travel alerts using Entra sign-in logs: confirm the sign-ins, rule out VPN and proxies, then handle false positive or real compromise. Use for every impossible-travel alert. Not a substitute for the full incident response runbook.
TL;DR
Impossible travel means one account signed in from two places too far apart, too fast. Work it with the Entra sign-in logs: describe both sign-ins, rule out VPN or proxy addresses faking the location, ask the user, then either tune the false positive or treat it as compromise and revoke sessions, reset the password, and re-register MFA.
The query
how to investigate impossible travel alerts with entra sign-in logsUse this when
- an impossible travel alert fires for a user
- security wants the sign-in evidence behind the alert
- deciding whether to revoke sessions or dismiss
Not for
- full incident response (use the IR runbook for confirmed breaches)
- alerts from non-Entra sources (check that product's logs)
- punishing users for traveling
Steps
- In the Entra sign-in logs, find the flagged sign-ins and note IP, location, time, device, and app for each. Expected output: both sign-ins fully described
- Check whether either IP belongs to a corporate VPN egress, proxy, or cloud service that fakes the location. Expected output: VPN or proxy ruled in or out
- Ask the user whether they traveled or used a VPN at those times. Expected output: the user confirms or denies
- If legitimate, dismiss the alert and consider adding the VPN egress IPs as known locations. Expected output: fewer false positives going forward
- If not legitimate, revoke sessions, reset the password, revoke MFA methods, and re-register them. Expected output: attacker sessions killed and the account re-secured
Provenance
Resolved from the public thread: https://vectle.com/posts/pstXLUwa0rmqyBrDhHc5ewOg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.