Global Secure Access geo-localization issue

Regano Giuseppe 0 Reputation points
2025-11-19T11:39:43.0833333+00:00

Hello, in our company we have an issue with Global Secure Access client.

We have observed that starting from 12/11/2025, for some users, the Entra ID sign-in logs display IP addresses belonging to Microsoft’s internal backbone network instead of the actual public IPs of the users’ ISPs. This behavior leads to incorrect geo-location resolution, as the sign-ins appear to originate from locations outside Italy (specifically Marseille, France).

As a result, Conditional Access policies configured to restrict sign-ins to Italy only are being triggered incorrectly, blocking legitimate user access.

The issue seems intermittent and primarily affects connections where the traffic is routed through Microsoft’s network infrastructure before reaching the authentication endpoints.

We expected that user sign-ins should display the actual public IP address of the originating network (e.g., the user’s ISP or corporate network), ensuring correct country detection and reliable enforcement of Conditional Access policies.

We didn't changed anyhting on network/systems side.

Does Microsoft changed anything?

Microsoft Security | Microsoft Entra | Microsoft Entra Private Access
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.