Travel Alerting

Bilal Beyah 20 Reputation points
2025-04-24T17:04:42.3866667+00:00

So I am a little familiar with Atypical Travel Alerts and Impossible Travel. Is there a way to setup just travel alerts?

The Example a U.S. Employee was only hired in to work remotely in the U.S. So i would only expect U.S. based locale data. Is there way to generate an alert if that employee is signing in with a locale other than U.S.?

I wouldn't want to apply it to all employees as there are some employees that are hired to work in other countries.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
258 questions
0 comments No comments
{count} votes

Accepted answer
  1. Catherine Kyalo 1,540 Reputation points Microsoft Employee
    2025-04-28T08:15:33.2866667+00:00

    Hi Bilal Beyah

    Here is my recommendation:

    1. Create a Dynamic Group -create a dynamic group that includes only the employees who are expected to work from specific locations, such as the U.S. (Assumption that you have the location attribute updated in Azure Active Directory)
    2. Creating a Detection Rule for the Dynamic Group - create a custom detection rule that applies to the dynamic group you created. This rule will monitor sign-ins and generate alerts when the identity logon event locale is not in the U.S. - Refer: https://learn.microsoft.com/en-us/defender-xdr/custom-detection-rules

    Another option is that you can Create Defender for Cloud Apps anomaly detection policies

    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.