Share via

Incorrect Public IP Location on Microsoft Entra

Nipat Bengthong 0 Reputation points
2026-03-25T04:34:31.5566667+00:00

Dear Microsoft Support,

We have observed an incorrect location being displayed for one of our customer’s public IP addresses in Microsoft Entra. Details are below:

IP Address: <PII REMOVED>

Incorrect Location Displayed: <PII REMOVED>

Correct Location: <PII REMOVED>

Correlation ID: sent private

This incorrect location is causing an impact on the customer’s security and conditional access policy enforcement. Kindly help to correct the geolocation record for this IP address.

Best regards,

Microsoft Security | Microsoft Entra | Microsoft Entra Internet Access

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-25T04:34:43.19+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Microsoft Entra determines location based on the public IP address seen during sign-in and evaluates Conditional Access policies (including location-based policies and Continuous Access Evaluation) using that IP and its mapped location.

    From the provided context, there is no mechanism described to directly edit or override the geolocation record of a specific public IP address within Microsoft Entra. Instead, Conditional Access guidance focuses on controlling access by IP ranges and handling cases where IP or location evaluation causes unexpected blocks.

    To mitigate impact on security and Conditional Access enforcement when location is not evaluated as desired, the supported approach is to rely on IP-based named locations rather than city-level geolocation:

    1. Identify the exact public IP address or range used by the customer (for example, 161.82.186.138 and any related egress IPs).
    2. In the Microsoft Entra admin center, go to Entra IDConditional AccessNamed locations.
    3. Create or update a named location that includes this public IP (or range) as an IPv4 range, and optionally mark it as a trusted location if appropriate for the organization’s policies.
    4. Update Conditional Access policies to use this named location (include or exclude it as needed) instead of relying on the inferred geographic location.

    This approach ensures that Conditional Access decisions are based on the explicitly configured IP ranges, independent of the city-level geolocation mapping, and is the documented way to avoid incorrect enforcement due to IP/location interpretation.

    If strict location enforcement with Continuous Access Evaluation is in use and users are being blocked unexpectedly, sign-in logs and the IP address (seen by resource) field should be reviewed, and any legitimate egress IPs should be added to named locations to prevent unintended blocks.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.