Source Ip Restoration
In brief
- It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks).
What Entra admins need to know
Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.
- It improves the accuracy of risk detection in Microsoft Entra ID Protection risk detections.
- It elevates your threat detection and response by recording accurate source IP in Microsoft Entra sign-in logs and in Microsoft Entra audit logs.
Prerequisites
- Administrators who
interact withGlobal Secure Accessfeaturesconfigure source IP restoration settings must havebothone of the following roleassignments depending on the tasks they're performing:assignments:- The Global Secure Access Administrator role
role to manage the Global Secure Access features. - The
Conditional Access Administrator to create and interact with Conditional Access policies.Global Administrator role
- The Global Secure Access Administrator role
- The product requires Microsoft Entra ID P1 licenses. For details, see the licensing section of What is Global Secure Access. If needed, you can purchase licenses or get trial licenses.
- You must enable the Microsoft Traffic Profile to use
Sourcesource IP restoration.
Known limitations
[!INCLUDE known-limitations-include]
Enable Global Secure Access signaling for Conditional AccessMicrosoft Entra ID and Microsoft Graph
:::image type="content" source="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png" alt-text="Screenshot showing the toggle to enable Conditional Access Signaling for Microsoft Entra ID." lightbox="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png":::
Sign-in log behavior
Related content
@@ -16,22 +16,20 @@ Source IP restoration is part of the Adaptive Access feature of Microsoft Entra - It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks). - It elevates your threat detection and response by recording accurate source IP in [Microsoft Entra sign-in logs](/azure/active-directory/reports-monitoring/concept-all-sign-ins) and in [Microsoft Entra audit logs](/entra/identity/monitoring-health/concept-audit-logs). -> [!NOTE]-> To achieve source IP restoration for non-Microsoft apps, you must also configure Conditional Access policies and ensure traffic flows through a compliant network. For more information, see [Enable compliant network check with Conditional Access](/entra/global-secure-access/how-to-compliant-network#protect-your-resources-behind-the-compliant-network).- ## Prerequisites -- Administrators who interact with **Global Secure Access** features must have both of the following role assignments depending on the tasks they're performing:- - The [Global Secure Access Administrator role](/azure/active-directory/roles/permissions-reference) role to manage the Global Secure Access features.- - The [Conditional Access Administrator](/azure/active-directory/roles/permissions-reference#conditional-access-administrator) to create and interact with Conditional Access policies.+- Administrators who configure source IP restoration settings must have one of the following role assignments:+ - The [Global Secure Access Administrator role](/azure/active-directory/roles/permissions-reference)+ - The [Global Administrator role](/azure/active-directory/roles/permissions-reference) - The product requires Microsoft Entra ID P1 licenses. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, you can [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).-- You must enable the [Microsoft Traffic Profile](concept-microsoft-traffic-profile.md) to use Source IP restoration.+- You must enable the [Microsoft Traffic Profile](concept-microsoft-traffic-profile.md) to use source IP restoration. ### Known limitations [!INCLUDE [known-limitations-include](../includes/known-limitations-include.md)] -## Enable Global Secure Access signaling for Conditional Access+<a name="enable-global-secure-access-signaling-for-conditional-access"></a>+## Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph > [!NOTE] > Source IP restoration is now enabled by default for new tenants. If you enabled Global Secure Access features in your tenant before June 2025, you might need to explicitly enable source IP restoration.@@ -47,7 +45,7 @@ By using this functionality, Microsoft Entra ID and Microsoft Graph receive the :::image type="content" source="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png" alt-text="Screenshot showing the toggle to enable Conditional Access Signaling for Microsoft Entra ID." lightbox="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png"::: > [!CAUTION]-> If your organization has active Conditional Access policies based on IP location checks, and you disable Global Secure Access signaling in Conditional Access, you might unintentionally block targeted end users from accessing the resources. If you must disable this feature, first delete any corresponding Conditional Access policies. +> If you create Conditional Access policies based on IP location checks, and you disable Global Secure Access signaling, you might unintentionally block targeted end users from accessing the resources. If you must disable this feature, first delete any corresponding Conditional Access policies. ## Sign-in log behavior @@ -64,7 +62,5 @@ Sign-in log data might take some time to appear. This delay is normal because th ## Related content -- [Set up tenant restrictions v2 (preview)](/azure/active-directory/external-identities/tenant-restrictions-v2) - [Enable compliant network check with Conditional Access](how-to-compliant-network.md)-- [Strictly enforce location policies using continuous access evaluation](../identity/conditional-access/concept-continuous-access-evaluation-strict-enforcement.md) - [Microsoft Traffic Profile](concept-microsoft-traffic-profile.md) 