๐ฉ๐ดNLOC - Non-Trusted Countries
One does not simply sign in from Mordor. This is the list of countries your tenant treats as Mordor, in one place, ready to block.
What this location is about ๐โ
A Named Location is not a policy, it is a reusable label. This one gathers the countries your business has no legitimate reason to sign in from, so that instead of maintaining a country list inside every geo-policy, you maintain it once here and point the policies at it. Change the world, or change your mind about a country, in one spot.
The MKB-friendly way to build it is by exclusion: rather than trying to name every hostile country, define your handful of operating countries and treat everything else as non-trusted. A Dutch or Belgian business that never signs in from outside the EU has a very short allow-list and a very long, self-maintaining block-list.
On its own, this location does nothing. It is the ammunition, not the gun. The blocking happens in the policies below that reference it. Get the list right here, and every policy that uses it is right for free.
Why this matters ๐ต๏ธโ
Geography is a crude signal, and a genuinely useful one. Most MKB tenants sign in from two or three countries, ever. A sign-in from the other hundred-and-ninety is not proof of an attack, but it is a cheap, high-signal reason to slam the door: the attacker renting a botnet in a far-off data centre trips it constantly, while your users never notice a policy they never cross.
Centralising the list matters because geo-policy sprawl is where mistakes hide. Five policies each with their own hand-typed country list drift apart the moment someone edits one and forgets the rest. One Named Location, referenced everywhere, cannot disagree with itself.
๐ ๏ธ Configurationโ
Where: Entra admin center โ Protection โ Conditional Access โ Named locations โ Countries location.
- Create a Countries location and select either the countries to treat as hostile or, better, tick your operating countries and invert the logic in the policy so everything else is caught.
- Determine location by IP address or GPS; IP is the pragmatic default for the MKB baseline.
- Do not mark it trusted. This is the opposite of trusted, and the naming (๐ด) says so.
- Leave "include unknown countries/regions" switched off unless you have a reason: an unresolvable location is its own small risk decision.
This one is safe to define eagerly, since it changes nothing until a policy points at it. The care goes into the policies, which should always be staged in Report-only first.
Caveats โ ๏ธโ
Geo is bypassable, and still worth it. A VPN or a hop through an allowed country defeats a country block, so this is a speed bump, not a wall. It belongs in a layered baseline alongside MFA and device compliance, not as a lonely hero. Cheap signal, real value, no illusions.
The allow-list is the thing to get right. Since the smart build is "everything except our countries", the risk is forgetting a country your business genuinely uses. A user stuck at an airport abroad is the classic false positive. Keep the operating-country list current and known.
License and reversibility. Named Locations are core Entra ID P1, included in Business Premium. Clean-revert: delete or edit the list and the policies pointing at it adjust instantly, which is exactly why a quietly-widened non-trusted list belongs in drift detection.
๐ Relatedโ
- ๐ฆ๐ด๐ฉCA - Block Non-Trusted Countries All Cloud Apps: the hard door this list feeds.
- ๐ฆ๐ด๐ฉCA - Block Non-Trusted Countries RegSecInfo: stops new MFA registration from these countries.
- ๐ฉ๐ NLOC - Less-Trusted Countries: the amber tier, for countries you distrust but do not outright block.
You cannot keep the whole world out, but you can stop pretending the whole world is a customer. Name the places you never work from, and the door writes itself. ๐