Skip to content

Update named location

Azure

Update named location

service: Azure - Conditional Access, Named Locations
techniques:

Event

Changes an IP-based or country-based named location. Marking an IP location trusted can affect policies that include/exclude trusted locations and risk calculations. It does not automatically exempt every sign-in from MFA; impact depends on actual policy references and the public source address Entra evaluates.

Security Context

Unauthorized expansion of a trusted location can weaken authentication controls (T1556.009). Approved corporate-egress changes are also common. An address being listed is not proof of an attacker-controlled route or successful access.

Log Source

Microsoft Entra directory audit logs, illustrated with activityDisplayName: Update named location. Match result, actor, and target IDs. Graph-style exports and Azure Monitor wrappers differ; exact modified-property and additionalDetails serialization still needs captured-log validation.

Key Fields

FieldInvestigation value
activityDisplayName, resultRecorded activity and outcome.
initiatedBy, correlationIdActor and related changes; verify actual administrative authority.
targetResourcesTarget ID/type and illustrative old/new properties.
additionalDetailsOptional method/client context; do not assume all exports expose full values.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Compare old/new CIDRs and trust status and verify ownership and approved network changes.
  3. Identify policies referencing this location ID or all trusted locations, including whether the location is included or excluded.
  4. Correlate observed public source IP, proxy/VPN behavior, and sign-in policy results.

Sample Event

Synthetic scenario. The sample adds 203.0.113.66/32 and changes isTrusted from false to true. The previous definition was not marked trusted; actual dependent policy behavior is absent.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000100011111_2B4D8_82148710",
"category": "Policy",
"correlationId": "90000000-0000-4000-8000-000100011111",
"result": "success",
"resultReason": "",
"activityDisplayName": "Update named location",
"activityDateTime": "2026-04-15T18:18:23.7218042Z",
"loggedByService": "Conditional Access",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "60000000-0000-4000-8000-000011101101",
"displayName": "Corporate-Office-Egress",
"type": "Other",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": [
{
"displayName": "ipRanges",
"oldValue": "[{\"@odata.type\":\"#microsoft.graph.iPv4CidrRange\",\"cidrAddress\":\"198.51.100.0/24\"}]",
"newValue": "[{\"@odata.type\":\"#microsoft.graph.iPv4CidrRange\",\"cidrAddress\":\"198.51.100.0/24\"},{\"@odata.type\":\"#microsoft.graph.iPv4CidrRange\",\"cidrAddress\":\"203.0.113.66/32\"}]"
},
{
"displayName": "isTrusted",
"oldValue": "[false]",
"newValue": "[true]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"ipRanges, isTrusted\""
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1556.009 — Conditional Access Policies — Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts. Conditional access policies are additional verifications used by identity providers and identity and access management systems to determine whether a user should be granted access to...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.