Source Ip Restoration
In brief
- It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks).
Documentation change
- It improves the accuracy of risk detection in Microsoft Entra ID Protection risk detections.
- It elevates your threat detection and response by recording accurate source IP in Microsoft Entra sign-in logs and in Microsoft Entra audit logs.
Prerequisites
- Administrators who interact with Global Secure Access features must have both of the following role assignments depending on the tasks they're performing:
- The Global Secure Access Administrator role role to manage the Global Secure Access features.
- The Conditional Access Administrator to create and interact with Conditional Access policies.
- Administrators who configure source IP restoration settings must have one of the following role assignments:
- The product requires Microsoft Entra ID P1 licenses. For details, see the licensing section of What is Global Secure Access. If needed, you can purchase licenses or get trial licenses.
- You must enable the Microsoft Traffic Profile to use Source IP restoration.
- You must enable the Microsoft Traffic Profile to use source IP restoration.
Known limitations
[!INCLUDE known-limitations-include]
Enable Global Secure Access signaling for Conditional Access
:::image type="content" source="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png" alt-text="Screenshot showing the toggle to enable Conditional Access Signaling for Microsoft Entra ID." lightbox="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png":::
Sign-in log behavior
Related content
diff --git a/docs/global-secure-access/how-to-source-ip-restoration.md b/docs/global-secure-access/how-to-source-ip-restoration.md index 68a9d678894..c7d37a65dfc 100644 --- a/docs/global-secure-access/how-to-source-ip-restoration.md +++ b/docs/global-secure-access/how-to-source-ip-restoration.md @@ -16,22 +16,20 @@ Source IP restoration is part of the Adaptive Access feature of Microsoft Entra - It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks). - It elevates your threat detection and response by recording accurate source IP in [Microsoft Entra sign-in logs](/azure/active-directory/reports-monitoring/concept-all-sign-ins) and in [Microsoft Entra audit logs](/entra/identity/monitoring-health/concept-audit-logs). -> [!NOTE] -> To achieve source IP restoration for non-Microsoft apps, you must also configure Conditional Access policies and ensure traffic flows through a compliant network. For more information, see [Enable compliant network check with Conditional Access](/entra/global-secure-access/how-to-compliant-network#protect-your-resources-behind-the-compliant-network). - ## Prerequisites -- Administrators who interact with **Global Secure Access** features must have both of the following role assignments depending on the tasks they're performing: - - The [Global Secure Access Administrator role](/azure/active-directory/roles/permissions-reference) role to manage the Global Secure Access features. - - The [Conditional Access Administrator](/azure/active-directory/roles/permissions-reference#conditional-access-administrator) to create and interact with Conditional Access policies. +- Administrators who configure source IP restoration settings must have one of the following role assignments: + - The [Global Secure Access Administrator role](/azure/active-directory/roles/permissions-reference) + - The [Global Administrator role](/azure/active-directory/roles/permissions-reference) - The product requires Microsoft Entra ID P1 licenses. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, you can [purchase licenses or get trial licenses](https://aka.ms/azureadlicense). -- You must enable the [Microsoft Traffic Profile](concept-microsoft-traffic-profile.md) to use Source IP restoration. +- You must enable the [Microsoft Traffic Profile](concept-microsoft-traffic-profile.md) to use source IP restoration. ### Known limitations [!INCLUDE [known-limitations-include](../includes/known-limitations-include.md)] -## Enable Global Secure Access signaling for Conditional Access +<a name="enable-global-secure-access-signaling-for-conditional-access"></a> +## Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph > [!NOTE] > Source IP restoration is now enabled by default for new tenants. If you enabled Global Secure Access features in your tenant before June 2025, you might need to explicitly enable source IP restoration. @@ -47,7 +45,7 @@ By using this functionality, Microsoft Entra ID and Microsoft Graph receive the :::image type="content" source="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png" alt-text="Screenshot showing the toggle to enable Conditional Access Signaling for Microsoft Entra ID." lightbox="media/how-to-source-ip-restoration/enable-conditional-access-signaling.png"::: > [!CAUTION] -> If your organization has active Conditional Access policies based on IP location checks, and you disable Global Secure Access signaling in Conditional Access, you might unintentionally block targeted end users from accessing the resources. If you must disable this feature, first delete any corresponding Conditional Access policies. +> If you create Conditional Access policies based on IP location checks, and you disable Global Secure Access signaling, you might unintentionally block targeted end users from accessing the resources. If you must disable this feature, first delete any corresponding Conditional Access policies. ## Sign-in log behavior @@ -64,7 +62,5 @@ Sign-in log data might take some time to appear. This delay is normal because th ## Related content -- [Set up tenant restrictions v2 (preview)](/azure/active-directory/external-identities/tenant-restrictions-v2) - [Enable compliant network check with Conditional Access](how-to-compliant-network.md) -- [Strictly enforce location policies using continuous access evaluation](../identity/conditional-access/concept-continuous-access-evaluation-strict-enforcement.md) - [Microsoft Traffic Profile](concept-microsoft-traffic-profile.md)