Skip to main content

ITDR Approve Locations

Updated today

Overview:

The Approved Location module is an ITDR security control that enforces location-based access for user logins. It evaluates login attempts against a defined list of approved locations and can automatically suspend users accessing from unapproved locations, without MDR involvement. This ITDR capability supports automatic mitigation.

Login locations are determined using IP geolocation. Supported location types include:

  • IP addresses

  • Countries

  • US states

Please note:

  • This feature is currently supported by Microsoft 365 workspaces only.

  • City-level locations are no longer supported due to reliability limitations. Any previously configured cities will be removed automatically (this is also relevant for ITDR of Google workspaces).

  • VPN provider detection is not yet supported; IP ranges can be defined manually.


Operating Modes

The module supports three operating modes, allowing gradual rollout and tuning:

  • Accuracy Mode
    Optimizes detection logic to reduce false positives. No incidents are created and there is no impact on user experience.

  • Alerting Mode
    Creates an incident for every login from an unapproved location, without suspending users. Intended for tuning approved locations before enforcement.

  • Enforcement Mode
    Automatically suspends users logging in from unapproved locations. Incidents are created but not reviewed by the MDR team. MSPs are responsible for reviewing incidents and releasing users directly from the incident when required.


Configuring the Feature

  • Go to the ‘ITDR’ section in the ‘Security Controls’ tab

  • Enable the 'Approved Locations' option

  • Whitelist the relevant locations / IPs by clicking on 'Manage Whitelist'

  • Select the desired operating mode

Did this answer your question?