Wealth management

Geo-blocking tells you where a sign-in came from. Not who.

In three days this past April, Microsoft tracked a phishing wave that reached more than 13,000 organizations.

1 min readOriginally posted on LinkedIn

In three days this past April, Microsoft tracked a phishing wave that reached more than 13,000 organizations. Financial services was one of the hardest-hit industries in it.

The lure was boring on purpose: an email about an internal review, a PDF, a link, a "Sign in with Microsoft" page. That page wasn't Microsoft. It sat in the middle, passed everything through to the real login, and captured the session after the multi-factor prompt was approved. Real credentials. Real second factor. Both handed to someone else in real time.

I bring it up because a lot of firms I talk to have a geo-block in place, no sign-ins from outside the US, and treat that as the perimeter. It isn't. A geo-block answers one question: what country did this come from. It does not answer whether the person signing in works for you.

Travel alerts are the other half of that comfort. Two sign-ins too far apart to be the same human is a useful signal. But Microsoft calculates it after the fact, not at the door, and it needs about two weeks of history on a user before it says anything. It also sits on a license tier plenty of small firms are not paying for, so it never fires at all.

The control that actually closes this door is phishing-resistant sign-in: passkeys, Windows Hello. Then there is no session worth stealing.

Worth confirming which layer you are actually relying on before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions