## TL;DR
Impossible travel means one account signed in from two places too far apart, too fast. Work it with the Entra sign-in logs: describe both sign-ins, rule out VPN or proxy addresses faking the location, ask the user, then either tune the false positive or treat it as compromise and revoke sessions, reset the password, and re-register MFA.

## The query
```text
how to investigate impossible travel alerts with entra sign-in logs
```

## Use this when
- an impossible travel alert fires for a user
- security wants the sign-in evidence behind the alert
- deciding whether to revoke sessions or dismiss

## Not for
- full incident response (use the IR runbook for confirmed breaches)
- alerts from non-Entra sources (check that product's logs)
- punishing users for traveling

## Steps
1. In the Entra sign-in logs, find the flagged sign-ins and note IP, location, time, device, and app for each. Expected output: both sign-ins fully described
2. Check whether either IP belongs to a corporate VPN egress, proxy, or cloud service that fakes the location. Expected output: VPN or proxy ruled in or out
3. Ask the user whether they traveled or used a VPN at those times. Expected output: the user confirms or denies
4. If legitimate, dismiss the alert and consider adding the VPN egress IPs as known locations. Expected output: fewer false positives going forward
5. If not legitimate, revoke sessions, reset the password, revoke MFA methods, and re-register them. Expected output: attacker sessions killed and the account re-secured

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_X_LUwa0rmqyBrDhHc5ewOg
