Skip to main content

🚩🟠NLOC - Less-Trusted Countries

The Outer Rim of your tenant: not the core worlds, not quite Mordor. Countries you can travel through, but only on trusted equipment.

🚩Type Named location (countries)🟠Trust Less-trusted
reference-build · nloc-less-trusted-countriesGolden Master reference
License tier
Business Premium (Entra ID P1)
Control plane
Entra Named Locations
Definition
Countries / regions
Reversibility
clean-revert

What this location is about 🧭

Not every country is either home or hostile. Some sit in between: a place a user occasionally travels to, a region a supplier operates from, somewhere you do not want to block outright but do not want to wave through either. This Named Location gathers those amber countries in one label, so policies can ask for more proof there instead of a flat yes or no.

Where the Non-Trusted list is a wall, this is a checkpoint. Same idea, gentler action.

🤔 Amber, not red

The point of a middle tier is to avoid two bad extremes: blocking a country your people genuinely visit, or trusting one you only half-know. Sign-ins from here are allowed, but only on terms, a compliant device, a fresh phishing-resistant proof, whatever the referencing policy demands.

Why this matters 🕵️

A two-state world, trusted or blocked, forces bad calls. Block a country your sales lead visits twice a year and you generate a support ticket every trip; trust it and you have handed an attacker in that region the same free pass as your own office. The amber tier is how you say "fine, but prove it", which is usually the honest answer.

Like its red sibling, it earns its keep by centralising. One list, referenced by the step-up policies, means the definition of "somewhere we are cautious about" lives in exactly one place and cannot quietly diverge across policies.

🛠️ Configuration

Where: Entra admin centerProtectionConditional AccessNamed locationsCountries location.

  • Create a Countries location and select the regions you want to treat as amber, the ones you deal with occasionally but do not fully trust.
  • Determine by IP address for the baseline.
  • Do not mark it trusted. Amber is not green.
  • Keep it distinct from the non-trusted list: a country belongs in one tier or the other, never both, or the stricter policy will win in ways you did not intend.

Nothing happens until a policy references it, so define it freely and put the caution into the policies, always staged in Report-only first.

Caveats ⚠️

Tier discipline matters. A country in both the amber and red lists will be hit by whichever policy is stricter, usually the block, which makes the amber intent pointless. Decide the tier per country and keep them mutually exclusive.

Step-up still assumes the step exists. "Require a compliant device from here" only helps if your devices actually reach compliance. The amber tier leans on the device policies being real; without them, "less-trusted" quietly becomes "trusted".

License and reversibility. Named Locations are Entra ID P1, included in Business Premium. Clean-revert, and a country that drifts from amber to forgotten is exactly the kind of quiet change worth reviewing on a schedule.


Between the front door and the locked gate there is a checkpoint, and some countries belong at it. Amber is the tier that lets you be careful without being blunt. 🧭