How to Create a Conditional Access Policy in Entra ID to Block Foreign Logins

IT Consultancy & Repairs, located in Crewe, servicing Cheshire and surrounding areas.

How to Create a Conditional Access Policy in Entra ID to Block Foreign Logins

One of the easiest ways for cybercriminals to compromise a business account is by exploiting weak or stolen credentials from completely different parts of the world. If your workforce is based entirely within one country, there is no reason to leave your digital doors open to global login attempts. Locking down access by geography drastically shrinks your attack surface.

Using Microsoft Entra ID (formerly Azure AD), you can deploy a Conditional Access Policy that evaluates where a login originates. If an attempt comes from outside your approved borders, Entra ID stops it dead in its tracks before the user can even attempt a password or Multi-Factor Authentication (MFA) prompt.

Here is a step-by-step guide to configuring a geo-location policy specifically for the United Kingdom.

Prerequisites Before You Start

To implement this policy, your organisation must meet a couple of technical requirements:

  • Licensing: You need a licence tier that includes Microsoft Entra ID Plan 1 or Plan 2 (such as Microsoft 365 Business Premium or E3/E5 plans).
  • Privileges: Your account needs to hold either the Conditional Access Administrator or Global Administrator role to make these changes.

Step 1: Define the UK Location Target

Before building the actual restriction rule, you need to tell Entra ID exactly what area counts as the United Kingdom.

  1. Sign in to the Microsoft Entra admin center.
  2. Expand the Protection menu on the left sidebar and select Conditional Access.
  3. Under the “Manage” subsection, click on Named locations.
  4. Click + Countries location at the top of the pane.
  5. Name your location clearly (e.g., Approved Country - UK).
  6. Select Determine location by IP address (IPv4 and IPv6).
  7. Search for and check the box next to United Kingdom, then click Create.

Step 2: Build the Conditional Access Policy

Now that Entra ID recognises the UK as a specific zone, you can construct the rule to block everything else.

  1. Still within the Conditional Access menu, click on Policies and select + New policy.
  2. Give your policy an explicit name, such as CA001: Block All Access Outside UK.

Assignments (Who and What)

  • Users: Under Users, choose All users.

    Crucial Safety Tip: Always go to the Exclude tab and select at least one emergency administrator account (“break-glass” account). This ensures you won’t accidentally lock yourself out if Microsoft misidentifies your own IP address location.
  • Target resources: Select All cloud apps. This applies the shield across Outlook, Teams, SharePoint, and all connected services.

Conditions (Where)

  • Click on Locations and toggle the switch to Configure: Yes.
  • On the Include tab, select Any location. (This target tells the policy to look at all traffic worldwide).
  • Switch to the Exclude tab, select Selected locations, and check the box for the Approved Country - UK zone you created in Step 1.

Why do it this way? By including “Any location” and excluding the “UK”, the policy automatically targets every single country in the world except the United Kingdom.

Access Controls (The Action)

  • Under the Grant section, select Block access and click the Select button.

Step 3: Test and Enable Safely

Never turn a restrictive security policy completely “On” immediately without testing it first. Doing so can cause massive disruption if a setting is misconfigured.

  • At the bottom of the screen, set the Enable policy toggle to Report-only.
  • Click Create.

In Report-only mode, Entra ID logs exactly what would have happened without actually blocking any users. Monitor your sign-in logs for a few days. Once you verify that legitimate UK-based staff are passing through safely and only foreign traffic is triggering hits, return to the policy settings, flip the toggle to On, and save to go live.

Tags: , , ,

Follow by Email
FbMessenger