EIDCA-010: Location-Based CA Policies Audit

Platform
Entra ID / M365
Category
Entra ID Conditional Access
Severity
Medium
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Location-based Conditional Access policies restrict access based on IP address ranges, countries, or named locations. Without location controls, attackers can authenticate from any geographic location, making it harder to detect and prevent unauthorized access from suspicious or high-risk regions.

Recommended value

Location-based policies configured to block or require additional controls for access from untrusted locations

Remediation

Review existing named locations and ensure trusted corporate IP ranges and countries are accurately defined. Create Conditional Access policies that require MFA or block access from untrusted locations, particularly for privileged accounts and sensitive applications. Regularly update named location definitions as corporate network infrastructure changes.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDCA-010
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-2(11), SC-7