Skip to content
Skip to main content
Cloud Services Technical Explainer

What is impossible-travel detection?

Impossible-travel detection compares two account events and flags that their estimated network locations are too far apart for one person to travel between them in the available time. It is a provider-generated risk assessment, not direct measurement of either person's physical location.

The calculation begins with two observations

Dave uses SharePoint from Northstar's London office at 09:03. Twelve minutes later, another event for his account appears from an IP address geolocated to Frankfurt. A provider may compare the two times and location estimates and generate a travel-risk detection.

Two records become one travel-risk signal
EstablishedThe provider linked two account observations and assessed their estimated locations and timing as implausible travel.
Still openWhether either estimate describes the user's location and whether the events came from different people, devices or network exits.

Network exits can move without the person moving

The IP address may describe a VPN exit, mobile gateway, corporate security service, cloud-hosted application or other intermediary. Geolocation databases are estimates and providers apply different behavioural models. A second device can also perform background activity while Dave is using the first.

Preserve both underlying events, not just the alert: full timestamps, IP addresses, sessions, devices, applications, authentication methods, resource actions and the provider's detection type, risk level and generation time. Then compare provider/network ownership, known VPN routes, device records and the account's normal pattern.

An unusual-location alert explains how to state the resulting proposition. What an IP address can establish supplies the provider-neutral reason the inferred location cannot be treated as a person's coordinates.

Current Microsoft Entra terminology - checked 2 September 2026

Microsoft Entra currently distinguishes atypical travel from impossible travel. Its atypical-travel model considers time, travel distance and past behaviour and says it ignores some obvious false-positive patterns such as familiar VPNs. Its impossible-travel detection uses Microsoft Defender for Cloud Apps activity and identifies geographically distant activity within a shorter period than travel would allow. Availability and calculation timing depend on licensing and product configuration.

Keep the exact provider label and its contemporary definition. Similar-sounding detections are not interchangeable.

The durable principle

Impossible travel is a comparison between provider observations. It is useful because it focuses attention on two sessions and their actions; it remains limited because network location is not the same proposition as human location.

The point to remember

Preserve the two events that produced the alert, then test their sessions, devices, applications and network exits. Do not turn estimated IP geography into proof of a person's travel.

Reference: CLD-043Cloud Services