ROPC Flows creating impossible travel - Identity Protection fails

Dale Puumala 1 Reputation point
2022-05-18T14:49:46.857+00:00

We are trying to utilize an ROPC user flow with a B2C tenant. When the user initially logs in, it shows their login from their hosted IP address wherever they are. Then the user flow shows another login that comes from our corporate IP address range. This is generating impossible travel scenarios and because of that users are getting blocked because we use Identity Protection. I believe what's happening is it senses the Sign-In as a medium risk sign-in, which then forces an MFA challenge. However you can't use MFA challenge through an ROPC user flow. So the login is blocked.

Does anyone have any suggestion on how we can address this problem?

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,652 questions
{count} votes

1 answer

Sort by: Most helpful
  1. 2022-05-19T05:37:09.007+00:00

    Hello @Dale Puumala , you can create Trusted Locations for both hosted and corp addresses IP ranges and exclude them from any applicable policy conditions.

    Let us know if this answer was helpful to you or if you need additional assistance. If it was helpful, please remember to accept it so that others in the community with similar questions can more easily find a solution.

    0 comments No comments