Scenario
Users at approved sites sign in fine, but traveling staff routed through company VPN or mobile carriers are unexpectedly blocked.
Recommended Resolution Path
- Review how Conditional Access evaluates source IP versus VPN egress and named locations.
- Check whether the policy mixes trusted location logic with device or risk requirements.
- Inspect real sign-in logs from the affected geography rather than reasoning from policy names alone.
- Tune exceptions narrowly and document the intended travel behavior.
Technician Notes
Document what changed, what confirmed the fix, and whether the issue points to a broader standards gap worth addressing for the client.
- Log in to post comments
Subjects