Have you ever seen a user's mobile data IP source change frequently (think 5 times in 20 minutes, but also that pattern repeated several times in one day)? It doesn't really seem malicious and there is no other supporting evidence to indicate such. The phone is enrolled in Intune. It is one mobile provider, the user is not reported as switching between providers which would be a red flag. I'm very aware that Geo-IP data is not entirely accurate especially when it comes to mobile phone providers. This user's geo-ip is popping from New York to the midwest and also California within 10-20 minutes and the frequent IP switching is something I've not seen behaviorally before. Wondering what legitimate case or problem might cause such behavior.