MCAS - Location Field

%3CLINGO-SUB%20id%3D%22lingo-sub-920966%22%20slang%3D%22en-US%22%3EMCAS%20-%20Location%20Field%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-920966%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20determines%20the%20location%20shown%20in%20MCAS%20for%20Office%20365%20logs%20other%20than%20users%20utilizing%20a%20VPN%20service%20on%20their%20devices%3F%20I'm%20seeing%20too%20many%20users%20having%20connections%20from%20different%20locations%20within%2030%20mins%20to%20an%20hour%20usually%20using%20Exchange%20and%20Sharepoint%20Online%20and%20this%20creates%20a%20lot%20of%20false%20positive%20Impossible%20Travel%20Activity%20alerts.%20How%20does%20CAS%20or%20Office%20365%20resolve%20these%20locations%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-920966%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-935287%22%20slang%3D%22en-US%22%3ERe%3A%20MCAS%20-%20Location%20Field%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-935287%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F291539%22%20target%3D%22_blank%22%3E%40acebq%3C%2FA%3EI%20believe%20the%20logs%20are%20reading%20the%20public%20facing%20IP%20address%20of%20the%20VPN%20exit%20node.%20If%20one%20of%20the%20IP%20addresses%20is%20the%20public%20facing%20IP%20of%20your%20VPN%20connection%20then%20you%20can%20add%20it%20to%20the%20list%20of%20trusted%20IP%20in%20the%20alert%20to%20stop%20it%20flagging%20impossible%20travel.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2071943%22%20slang%3D%22en-US%22%3ERe%3A%20MCAS%20-%20Location%20Field%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2071943%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F291539%22%20target%3D%22_blank%22%3E%40acebq%3C%2FA%3E%26nbsp%3BHi%2C%20I%20am%20facing%20the%20same%20challenge%2C%20trying%20to%20understand%20%2F%20reproduce%20the%20alerts%20on%20my%20own.%20its%20time%20consuming%26nbsp%3B%20to%20check%20the%20high%20number%20of%20impossible%20travel%20alerts%20understanding%20where%20is%20a%20false%20positive%20or%20is%20a%20true%20one.%20May%20i%20ask%20you%20how%20you%20do%20these%20kind%20of%20checks%20%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2072728%22%20slang%3D%22en-US%22%3ERe%3A%20MCAS%20-%20Location%20Field%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2072728%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F888139%22%20target%3D%22_blank%22%3E%40AlessandroAntonini%3C%2FA%3EIt's%20been%20hard%20for%20us%20as%20well%20specially%20when%20you've%20got%20global%20locations.%20I've%20only%20been%20able%20to%20reproduce%20and%20catch%20those%20that%20are%20using%20VPN%20to%20anonymize%20their%20IP%20and%20those%20that%20uses%20our%20Site-to-Site%20VPN.%20I%20also%20observed%20different%20behaviors%20when%20users%20connect%20to%20their%20OneDrive%20and%20results%20are%20very%20inconsistent.%20I%20go%20through%20them%20one%20by%20one%20but%20I%20try%20to%20focus%20on%20those%20unknown%20connections%20that%20generated%20a%20lot%20of%20suspicious%20events.%20I've%20noticed%20some%20IP%20Addresses%20are%20incorrectly%20resolved%20which%20led%20me%20to%20this%20question%20years%20ago.%20I'm%20still%20experiencing%20inaccuracy%20from%20time%20to%20time%20just%20like%20yesterday%20when%20an%20IP%20Address%20was%20resolved%20to%20be%20coming%20from%20Germany%20but%20it%20was%20actually%20coming%20from%20Zimbabwe.%20I'm%20still%20testing%20and%20observing%20these%20events.%20We've%20come%20across%20some%20True%20Positives%20over%20the%20years%20and%20have%20since%20utilized%20MFA%20in%20most%20locations%20to%20at%20least%20lessen%20our%20worries%20when%20we%20get%20overwhelmed%20with%20the%20number%20of%20Impossible%20Travel%20Activities%20that%20comes%20in.%20I%20can't%20be%20much%20help%20now%20but%20I%20will%20post%20here%20if%20I%20discovered%20anything%20that%20can%20substantially%20help%20the%20community.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

What determines the location shown in MCAS for Office 365 logs other than users utilizing a VPN service on their devices? I'm seeing too many users having connections from different locations within 30 mins to an hour usually using Exchange and Sharepoint Online and this creates a lot of false positive Impossible Travel Activity alerts. How does CAS or Office 365 resolve these locations?

3 Replies

@acebqI believe the logs are reading the public facing IP address of the VPN exit node. If one of the IP addresses is the public facing IP of your VPN connection then you can add it to the list of trusted IP in the alert to stop it flagging impossible travel.

@acebq Hi, I am facing the same challenge, trying to understand / reproduce the alerts on my own. its time consuming  to check the high number of impossible travel alerts understanding where is a false positive or is a true one. May i ask you how you do these kind of checks ? 

@AleA79It's been hard for us as well specially when you've got global locations. I've only been able to reproduce and catch those that are using VPN to anonymize their IP and those that uses our Site-to-Site VPN. I also observed different behaviors when users connect to their OneDrive and results are very inconsistent. I go through them one by one but I try to focus on those unknown connections that generated a lot of suspicious events. I've noticed some IP Addresses are incorrectly resolved which led me to this question years ago. I'm still experiencing inaccuracy from time to time just like yesterday when an IP Address was resolved to be coming from Germany but it was actually coming from Zimbabwe. I'm still testing and observing these events. We've come across some True Positives over the years and have since utilized MFA in most locations to at least lessen our worries when we get overwhelmed with the number of Impossible Travel Activities that comes in. I can't be much help now but I will post here if I discovered anything that can substantially help the community.