Named location accuracy
Compare configured IP ranges against the organization’s actual current egress points, including any recently added office or provider.
Independent IT security review
Conditional Access can name a location or network as trusted, but that label is a promise made by the firewall, VPN, and Wi-Fi configuration-not by the policy itself. This review checks whether the promise still holds.
A Conditional Access named location is a list of IP ranges someone entered at some point. The policy trusts that list completely; the review checks whether the list still matches reality.
Compare configured IP ranges against the organization’s actual current egress points, including any recently added office or provider.
Confirm whether anyone is notified when an ISP-assigned public IP changes, since a stale entry can silently stop granting-or silently keep granting-trust.
Check whether a VPN exit range is treated the same as an office network, and whether that equivalence still reflects who is allowed to use the VPN.
A new ISP, an SD-WAN redesign, a branch office, or a shift to remote work can all change what actually sits behind a trusted range-without anyone touching the Conditional Access policy itself.
Distinguish full-tunnel from split-tunnel VPN configurations, since split tunneling can let untrusted local traffic sit alongside a trusted session.
Confirm that every site’s actual internet breakout point is reflected in the trusted list, especially after a network redesign changes how branches reach the internet.
Verify that guest and corporate Wi-Fi are actually separated at the network layer, not only by a different SSID name.
‘Trusted network’ and ‘compliant device’ are two different signals that are sometimes treated as interchangeable. A policy that leans on network location alone can be satisfied by a personal device that happens to be on the right Wi-Fi.
Identify Conditional Access policies that grant access based on network location without also requiring a managed or compliant device.
Confirm that a guest or visitor network cannot, through misconfiguration, share an IP range the tenant treats as trusted.
Compare firewall and routing changes against the named-location list on a cadence, since the two are maintained by different people on different schedules.
A finding here can mean updating a named-location list, redesigning firewall or Wi-Fi segmentation, or deciding that a policy should stop relying on network signal at all.
Distinguish a quick correction to a stale IP list from a larger network-segmentation project that needs its own plan and owner.
Recognize that firewall, VPN, and ISP changes belong to whoever manages that infrastructure; the review identifies the gap and hands off the network change itself.
Set a trigger-a new office, a new ISP, an SD-WAN change-that should prompt revisiting the trusted-location list rather than waiting for a scheduled review.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.