You can screen for impossible travel with identity sign-in logs you already collect: group successful sign-ins by user, order them by time, and flag consecutive sign-ins whose implied travel speed is physically implausible. That check is a triage heuristic, not a behavioral model. It cannot tell a stolen password from a VPN session, so every flag needs a human review step, and the most common source of noise is the VPN itself.
What impossible travel means
Impossible travel describes two sign-ins for the same identity whose locations are too far apart for the elapsed time. If one sign-in comes from Chicago at 09:00 UTC and the next from Singapore at 09:40 UTC, the gap is more than 15,000 km in 40 minutes, roughly 22,000 km/h. No passenger flight can cover that distance in that time, so either the user is not physically moving between those points, or one of the two sign-ins is not coming from the user’s device.
Microsoft documents impossible travel as a named identity risk detection in Microsoft Entra ID Protection. It is a time-and-location anomaly and is evaluated from stored data rather than in real time. Your custom workflow can reproduce the core arithmetic, but it will not reproduce everything the vendor detection does.
Impossible travel and atypical travel are different detections
Microsoft separates two related detections that are often confused:
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Attribute | Impossible travel | Atypical travel |
|---|---|---|
| What it tests | Whether two sign-ins are too far apart for the time between them | Whether a sign-in location is unusual for that specific user, based on learned patterns |
| Per-user baseline | Not described as a learned baseline in the documentation reviewed | Yes; learns a new user’s patterns during an initial period of the earlier of 14 days or 10 logins |
| Documented licensing | Entra ID P2 plus standalone Microsoft Defender for Cloud Apps, or Microsoft 365 E5 with Enterprise Mobility + Security E5 | Microsoft Entra ID P2 |
| Evaluation | Offline detection using Defender for Cloud Apps information | Calculated offline |
Licensing is the part most likely to have changed since a document was written. Check your tenant’s current entitlements in Microsoft’s Entra ID Protection risk detection documentation (reviewed October 2026) before you assume either detection is available to you.
How do I detect impossible travel without UEBA?
A custom correlation check needs four things: successful sign-in events with a stable user identifier, a timestamp in a consistent time zone, a source IP address, and a way to convert that IP into an approximate location. Microsoft’s security operations guidance for Entra recommends monitoring sign-in logs and changes in IP address, and that is the foundation this approach builds on. Microsoft does not publish a portable query or a universal time threshold for this, so the steps below are a practical synthesis you must validate against your own log schema.
Step 1: Normalize the identity and the event
- Key every event to one user identifier. Prefer an immutable object ID over a display name or a mutable email alias, because aliases can change and create false splits.
- Keep only successful authentications. A failed password attempt from a distant country is a different signal and would otherwise inflate your results.
- Convert all timestamps to UTC before comparing them. Mixed time zones produce false impossible travel results more often than any other single error.
Step 2: Geolocate the source IP and sort the events
- Resolve each IP to a country, city, and coordinates using a geolocation database you can document. Record the database name and version, because accuracy varies by region and by network type, and city-level results are often approximate.
- Sort each user’s events by timestamp, then compare each event with the one immediately before it.
Step 3: Compute implied speed and flag the pair
- Calculate the great-circle distance between the two points and divide by the elapsed time to get an implied speed in km/h.
- Flag the pair when the implied speed exceeds a ceiling you have chosen and tested. A common starting point is about 900 km/h, roughly the cruise speed of a commercial airliner. This guide does not prescribe a value, and a ceiling that is too low will flag ordinary travel by air.
for each user_id, events sorted by utc_time:
for each consecutive pair (a, b):
if a.ip == b.ip: continue
km = great_circle_km(a.geo, b.geo)
hours = (b.time - a.time) / 3600
speed = km / max(hours, 0.001)
if speed > SPEED_CEILING_KMH and km > MIN_DISTANCE_KM:
emit_review_item(user_id, a, b, speed)
The minimum-distance check matters. Two sign-ins from neighboring cities can produce a high implied speed simply because the geolocated coordinates are imprecise, so requiring a meaningful separation removes much of that noise.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why do I get impossible travel alerts when users use a VPN?
A VPN changes the source IP that the identity provider sees. The IP then belongs to the VPN provider’s exit node, which may be in a different country from the user. If one user connects through a VPN in one country and then signs in directly from a home network, your check sees two locations that the user never actually traveled between. Microsoft’s Entra security operations guidance states this directly: “VPNs can cause false positives” (Microsoft Learn, “Microsoft Entra security operations for user accounts”).
The same problem appears in other forms. Mobile carriers use shared egress addresses that geolocate to a distant data center. Cloud-hosted applications sign in from provider IP ranges. Some users have split tunneling enabled, so one device switches networks in the middle of a session.
Tuning for VPNs without blinding the check
- Allowlist sanctioned corporate VPN egress ranges. Treat a sign-in from a known corporate exit as the organization’s network location, not as a foreign one. Keep the list current, because providers change egress ranges.
- Do not suppress every VPN or every distant location. A stolen credential can be used through a commercial VPN, so blanket exclusions create a blind spot an attacker can use deliberately.
- Use known travel context. Approved travel, a corporate calendar entry, or a ticket that records a planned trip can explain a pair. Store that context so the analyst does not have to rediscover it.
- Review repeated patterns separately. A user who alternates between two regions every day is an atypical-travel problem, not a series of isolated incidents. Track recurrence per user.
What to investigate before deciding
A flagged pair is a question, not an answer. Work through the following sequence and record the outcome for each item.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Confirm both events belong to the same user, and compare timestamps, IP addresses, locations, applications, device identifiers, and user-agent strings.
- Ask whether the user traveled, used a sanctioned VPN, or accessed the service through an organization-wide network location.
- Check the sign-in history for other unusual characteristics, such as a new device, an unfamiliar application, a legacy protocol, or a sign-in at an unusual hour.
- Check for correlated alerts on the same account, including mailbox rule changes, mass downloads, or privilege changes in the same window.
- Decide the outcome and act on it, as described below.
What to do with the result
- Confirmed legitimate: record the benign explanation, such as the trip, the sanctioned VPN, or the corporate exit. Tune the known infrastructure carefully, and only with a documented reason.
- Unauthorized or unexplained: hand the event to your incident process. Microsoft’s Entra risk investigation guidance describes marking a confirmed malicious sign-in as compromised, resetting credentials, and blocking access where warranted.
Custom correlation or built-in identity risk detection?
The two approaches solve overlapping problems with different trade-offs. The comparison below shows what each one establishes; where the evidence does not establish a value, the cell says so.
| Axis | Custom log correlation | Built-in identity risk detection (Microsoft Entra ID Protection) |
|---|---|---|
| Required log sources | Any identity sign-in log export or SIEM feed you already collect, with a usable IP and timestamp | Microsoft Entra sign-in data; impossible travel also draws on Microsoft Defender for Cloud Apps information |
| Per-user behavior baseline | None, unless you build one; the check compares consecutive events only | Atypical travel learns each user’s patterns during the earlier of 14 days or 10 logins |
| VPN and shared-egress handling | Only what you configure; allowlists and context must be maintained by hand | Microsoft states that VPNs can cause false positives; the documentation reviewed does not describe a configurable allowlist for this detection |
| Tuning and analyst burden | High; thresholds, geolocation accuracy, and allowlists require ongoing ownership | Lower for the detection logic itself; review of each risk item still requires an analyst |
| Licensing and retention | Depends on your existing log platform and retention period | Entra ID P2 plus standalone Defender for Cloud Apps, or Microsoft 365 E5 with Enterprise Mobility + Security E5, for impossible travel; Entra ID P2 for atypical travel |
| Response actions | Whatever your SOAR or manual process provides | Investigation and remediation actions documented in Microsoft’s Entra guidance |
A simple geographic rule does not reproduce a commercial UEBA model. A UEBA system weighs many behavioral signals against a learned profile for each user. The custom check here weighs one pair of events at a time, and its accuracy depends on your geolocation data and your allowlists. Treat it as a way to surface candidates for review, not as a detection with a measured hit rate.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Where Microsoft Sentinel fits
Microsoft Sentinel documents anomaly detections for specific VPN products and log sources. Those examples compare IP address, country or region, internet service provider, and user or organization patterns. They are UEBA anomalies in that product, and they are not evidence that every low-cost log platform offers comparable behavior. If you already run Sentinel, check its anomaly reference for the sources you ingest before building a parallel rule.
Rank #4
- Reversible insert tool for can wrenches.
- One end for SLC Cabinets. Other end for pin in head screws found in most Network Interface boxes.
If you do not, the custom workflow above is a reasonable starting point. Begin with one identity provider, one sign-in table, and a conservative speed ceiling, then review the output for two weeks before you tune anything.
Pulled together, the practical answer is this: correlate successful sign-ins per user, compute implied travel speed between consecutive geolocated IPs, filter known infrastructure and documented travel, and route what remains through a human investigation. Keep the VPN case in the review queue rather than suppressing it, and keep the built-in detection and the custom check separate in your reporting, since they measure different things.
Also keep in mind that the built-in Microsoft detections come with licensing requirements that the custom check does not, so a team on a lower tier should expect to own the logic, the allowlists, and the ongoing tuning themselves.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




