EIDCA-011: Named Locations Configuration Review

Platform
Entra ID / M365
Category
Entra ID Conditional Access
Severity
Medium
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Named locations define trusted and untrusted network boundaries used by Conditional Access policies. Misconfigured named locations can result in overly permissive access from untrusted networks or unnecessarily restricted access from legitimate corporate locations.

Recommended value

All named locations accurately reflect current corporate network boundaries with trusted locations marked appropriately

Remediation

Navigate to the Named Locations blade in the Entra admin center and review all configured locations for accuracy. Verify that trusted corporate IP ranges are up to date and that country-based locations align with organizational presence. Remove any stale or unused named locations and ensure trusted location flags are only applied to verified corporate networks.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDCA-011
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-2(11)