If impossible travel alerts are triggering for users with expected travel patterns, follow this article to troubleshoot the problem.
Symptoms
- Alerts firing on legitimate travel patterns
Cause
Allowed Countries have not been configured in Login Restrictions, so the system flags logins from countries that are part of normal operations for certain users, for example, sales teams or frequent travelers.
Resolution
- Review the flagged travel events to confirm they represent legitimate, expected travel.
- Check whether Allowed Countries have been configured in the Login Restrictions tab. For more information, see Configure Identity Threat Detection & Response.
- If Allowed Countries are not set, identify which countries are part of the users' normal operations.
- Confirm alerts stop firing for those locations after the configuration is saved.
Back to ITDR Guide