Team: Huntress Managed Identity Threat Detection and Response (ITDR)
Environment: Unwanted Access
Summary: The country, city, or VPN label in an ITDR report is sourced from a third-party IP intelligence provider. IP location is an estimate, and providers (including Microsoft) sometimes disagree. This article explains why, how to check a sign-in in a few minutes, and how to tell us when our location is wrong.
In This Article
What You Might See
Why This Happens
How To Verify The Sign-In
What To Do Next
Reporting An Incorrect Location
What You Might See
- An ITDR report shows a sign-in from one country, but Entra ID or an IP lookup site shows a different one.
- The location for the same IP changes between reports.
- An IP is labeled as a VPN or hosting provider when the user says they weren’t using one.
Why This Happens
An IP address isn’t tied to a physical location. Providers estimate location from registration records, routing data, and observed activity, and each provider uses different data on different update schedules. Differences are most common for:
- Cloud and hosting traffic, including Microsoft, AWS, and Google. The location is usually the data center or network hub, not the user.
- Satellite internet, such as Starlink. Traffic often exits in a different country from where the user is.
- Mobile carriers and eSIMs, especially travel or international eSIMs, often route through the carrier’s home country.
- Smaller regional ISPs whose address blocks may be registered in a neighboring country.
- Recently reassigned IPs. When a block changes owners, providers update at different speeds.
Huntress gets its location data from a third-party IP intelligence provider. The location shown is what our provider reported during the event analysis. If the provider updates its data later, the same IP may show differently in future reports.
How To Verify The Sign-In
-
Find the sign-in in Entra. Go to Entra admin center > Monitoring & health > Sign-in logs, and filter by the user and the time in the report. Open the event and compare the IP and Location.
Note: By default, sign-in logs are kept for about 7 days on Entra ID Free and 30 days on P1/P2. Check as soon as you receive the report.
-
Look up the IP in two or three other tools. Check who owns the IP (the ISP or company name), not just the country. An IP owned by the user’s home ISP, mobile carrier, or Starlink is a good sign that the sign-in could be legitimate, even if the country is wrong.
-
Ask the user. Were they traveling, using a phone hotspot, an eSIM, satellite internet, or a VPN? Did they use a new device or app?
-
Look for other warning signs. These raise concern even if the location turns out to be wrong:
- New MFA methods
- New inbox rules
- Unfamiliar applications or user agents
- Sign-ins from several countries in a short period
What To Do Next
- Legitimate sign-in: Reject the remediation steps so the SOC knows the activity is expected.
- Location wrong, but activity still suspicious: Act on the report. A wrong country label doesn’t make the sign-in safe.
- Can’t verify: Assume compromise and follow the remediation steps.
Reporting An Incorrect Location
If you’ve confirmed that our location is wrong, please provide us with:
- The IP address
- The location Huntress showed
- The correct location, and how you confirmed it (Entra, ISP ownership, user confirmation)
- The report ID and the time of the sign-in