top of page


Conditional Access Named Locations: Common Mistakes and How to Audit Them
A client's Conditional Access policy looked correct while sign-ins quietly bypassed MFA. The cause: a Named Location built from a CIDR list gone stale, entries inaccurate, missing, or pointing at ranges no longer controlled. This walks security architects and engineers through six ways Named Locations fail silently, what each costs in dwell time and false confidence, and the PowerShell and KQL checks to audit yours before an incident finds the gap.

Derek Morgan
Aug 116 min read
Start Your Cloud Journey
bottom of page