EntraID mis-locates IP addresses during sign-in events, creating false positives.

David Baxter 25 Reputation points
2025-05-09T16:20:11.2433333+00:00

False positive security alerts are being triggered when users have unsuccessful sign-in events from trusted locations which are our branch locations, but Entra ID is logging them as coming from a completely different city, despite using the correct IP.

In our particular example, the public IP of one of our branches is in Texas, but the sign in logs show Portland, OR as the sign in location, despite showing the correct IP and recognizing it as a trusted location.

How do we resolve this so the IP addresses are represented by the right geographical location?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Vigneshwar Duvva 2,225 Reputation points Microsoft External Staff Moderator
    2025-05-19T06:20:21.4933333+00:00

    Hello @David Baxter

    Thank you for sharing the required details via private message.

    The issue was related to an IP location mismatch. We collected the necessary information from you and engaged our Product team to investigate further. They have now resolved the issue from the back end.

    You should be able to see the correct location in the Azure portal for the affected IP addresses.

    We hope this information is helpful. Please feel free to reach out if you have any further questions or need additional assistance

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.