Microsoft 365 Security for Small Business: Why You Must Lock It Down by Country
Updated: Sep 1

Updated August 2026: I originally wrote this article about restricting Microsoft 365 access by country after working on a small business environment where account security had become a concern. At the time, I presented country blocking more broadly than I would today. I still use location based Conditional Access policies when they make sense for the business, but I would not tell every small business that Microsoft 365 must be locked down to the United States. The better question is whether employees have a legitimate reason to sign in from other countries and how location fits into the rest of the company's Microsoft 365 security.
For a small business whose employees work entirely in the United States and do not normally travel internationally for work, blocking authentication attempts from countries where the company has no legitimate business activity can be a useful additional control. A business with international employees, frequent travelers, overseas vendors or other legitimate access requirements needs a different approach. That distinction is important because Microsoft 365 security should be designed around how the business actually operates rather than applying the same security policy to every company.
Why Can Someone Try to Sign Into Microsoft 365 From Another Country?
Microsoft 365 is a cloud service, so an employee does not have to be sitting inside the company office to reach a Microsoft sign in page. That flexibility is one of the reasons businesses use Microsoft 365 in the first place. Employees can work from home, travel, use mobile devices and access company resources without being physically connected to an office network.
The same internet accessibility also means Microsoft can receive authentication attempts from locations where your employees may never actually work. That does not mean every foreign sign in attempt represents a successful compromise, and I would not look at an unfamiliar country in a log and automatically conclude that someone got into the account. What it does give me is another piece of information I can use when deciding what access should be permitted.
For some of the small businesses I manage, there is simply no legitimate reason for an employee to authenticate from certain parts of the world. In those environments, I may use Microsoft Entra Conditional Access to restrict access based on location. I consider that one layer of the security strategy, not the entire strategy.
What Is Microsoft Entra Conditional Access?
Conditional Access gives me a way to establish rules around access to Microsoft cloud resources. Instead of treating every authentication attempt exactly the same, Microsoft Entra can evaluate applicable signals and controls when deciding what should happen during access.
Depending on the environment, licensing and policy being designed, those decisions can involve things such as network location, device information, authentication strength and risk information. A policy might block access under certain conditions, require stronger authentication, or require the device to meet specific requirements. Some of those capabilities have additional licensing requirements, which is one reason I review Microsoft licensing along with the actual configuration instead of assuming that every Microsoft 365 tenant has the same security options available.
Country restrictions are simply one possible use of Conditional Access. They are useful when they correspond to the way the company actually operates, but they should not be confused with a complete Microsoft 365 security strategy.
Should a Small Business Block Every Country Except the United States?
For some businesses, I think restricting access by country makes sense. If a ten person company operates entirely in the United States, its employees do not travel internationally for work, and nobody has a legitimate business reason to authenticate from another country, there may be little benefit in allowing authentication from everywhere.
I would still make that decision after understanding the environment rather than enabling a blanket policy simply because the company is small. I want to know where employees work, whether anyone travels, how outside vendors access the environment, what applications are being used and whether there are exceptions that need to be accounted for. I also want a new Conditional Access policy tested before relying on it because a security control that unexpectedly locks legitimate users or administrators out creates its own problem.
This is one of the reasons I prefer reviewing Microsoft 365 as an environment instead of treating individual security settings as isolated projects. In Microsoft 365 Security for Small Business: What Actually Needs to Be Configured, I go further into the other controls I look at and why simply owning Microsoft 365 does not tell me how those controls have actually been configured.
What Happens If an Employee Travels Internationally?
This is exactly why I do not treat country blocking as a universal rule. If the owner of a company regularly travels internationally and needs access to Outlook, Teams, SharePoint or OneDrive while traveling, a policy that simply blocks every country outside the United States could interfere with legitimate work.
That does not mean the only alternatives are allowing everything or blocking everything. Conditional Access can be designed around multiple signals and requirements, depending on the environment and licensing. The appropriate approach might involve stronger authentication, managed devices, different policies for particular users or another design that accounts for how the business actually operates. The important part is knowing about those requirements before the policy is enforced.
Location itself also needs to be understood in context. Microsoft can determine network location using information such as the public IP address, and network architecture can affect the location Microsoft sees. I therefore use location as a useful security signal rather than treating a country shown in a sign in record as unquestionable proof of where a person was physically sitting.
Country Blocking Does Not Replace Strong Authentication
Even when I restrict access by country, I still want authentication properly configured. Someone being located in the United States does not make an authentication attempt trustworthy, and an attacker does not have to be physically overseas to attack a Microsoft 365 account. Geographic restrictions reduce certain opportunities. They do not replace MFA, passkeys, phishing resistant authentication or the other identity controls that may be appropriate for the environment.
Authentication is changing quickly enough that I recently completed a major refresh of The Truth About MFA: Why It Wasn't Enough for This Small Business. That article goes into the difference between traditional MFA methods and newer phishing resistant options such as passkeys and FIDO2 security keys. Rather than repeat all of that here, I think the important connection is simple: where an authentication attempt comes from and how the user proves who they are are two different security decisions.
Microsoft 365 Security for Small Business Goes Beyond Location
I also do not want a business owner walking away from this article thinking that blocking foreign sign ins means the Microsoft 365 environment is now secure. I want to understand administrative access, authentication, Conditional Access, devices, Microsoft Defender, SharePoint and OneDrive permissions, third party applications, backup and recovery, alerting and the other parts of the environment that matter to that particular business.
That broader review is what I do through my Microsoft 365 Tenant Security Review and Microsoft 365 Audit. The purpose is not to turn on every Microsoft feature simply because it exists. I want to understand what the business owns, what is currently configured and whether those controls make sense for the way employees actually work.
There is also an ongoing management piece that is easy to overlook. A Conditional Access policy that made perfect sense when it was created may need to change when the company hires remote employees, starts working with a new vendor or changes how employees travel. I discuss that side of the problem in Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment? because security policies need someone responsible for reviewing and maintaining them as the business changes.
What About Email Spoofing and Phishing?
Location based Conditional Access protects access to Microsoft resources under the conditions defined in the policy. It does not prevent every email attack, and it does not replace the controls used to protect a company's email domain from spoofing and impersonation.
SPF, DKIM, DMARC and Microsoft Defender for Office 365 protections address different parts of the email security problem. I cover those issues separately in Microsoft 365 Email Security for Law Firms: How One Law Firm Got Spoofed and What I Did to Fix It. Although that article comes from a law firm environment, the distinction applies to any small business using Microsoft 365. Protecting who can authenticate to an account and protecting how the company's email identity can be used are related security problems, but they are not the same thing.
Should You Block Foreign Microsoft 365 Sign Ins?
If your employees work only in the United States and there is no legitimate reason for Microsoft 365 authentication to originate from other countries, country restrictions may be a useful part of your Conditional Access strategy. I would not implement them in isolation, however, and I would not describe them as something Microsoft requires every small business to do.
My approach is to first understand the business. Where do employees actually work? Does anyone travel? What devices do they use? Are there vendors or outside users who need access? What Microsoft licensing does the company have? What authentication methods are employees using? What Conditional Access policies already exist?
Those answers tell me much more than simply asking whether foreign countries are blocked.
For many small businesses, the larger problem is that nobody knows the answers because the Microsoft 365 environment was configured years ago and has never been reviewed as a whole. If that is where your business is, the starting point does not have to be deciding which countries to block. It can simply be finding out what is currently configured and whether it still makes sense for the business you operate today.
Frequently Asked Questions About Microsoft 365 Country Restrictions
Can Microsoft 365 block sign ins from other countries?
Yes. Microsoft Entra Conditional Access can use network location as a signal and can be configured to block access from selected countries or regions. Whether that is appropriate depends on how the organization operates and the legitimate locations its users need to access Microsoft resources from.
Does Microsoft recommend blocking every country except the United States?
Microsoft documents blocking countries or regions where an organization never does business as a use case for Conditional Access, but that is different from saying every United States business should block the rest of the world. Location-based blocking is a policy decision that should reflect the organization's legitimate access requirements.
Does country blocking stop hackers?
No. Country blocking can reduce access from locations the business does not expect, but it does not prevent every account attack. Strong authentication, appropriate Conditional Access policies, device security, monitoring and the other controls relevant to the environment still matter.
Will Microsoft 365 work if I travel outside the United States?
That depends on the Conditional Access policies configured for your organization. If a policy blocks the country you are visiting, access may be blocked. International travel should therefore be considered when location-based policies are designed.
Do I need special Microsoft licensing for Conditional Access?
Yes. Microsoft currently requires Microsoft Entra ID P1 for Conditional Access. Microsoft 365 Business Premium includes access to Conditional Access capabilities. Some additional risk- based Conditional Access capabilities require Microsoft Entra ID Protection and different licensing, so I verify the licensing available in the particular tenant before designing policies.
Additional Resources
Microsoft Learn: Block Access by Location with Conditional Access
Microsoft's current guidance for using Conditional Access to block access from countries or regions where an organization does not expect authentication traffic.Microsoft Conditional Access: Block Access by Location
Microsoft Learn: Conditional Access Network Assignment
Microsoft explains how network location can be used as a Conditional Access signal, including countries, regions, IP information and other network locations, along with considerations for location based blocking.Microsoft Conditional Access Network Assignment
Microsoft Learn: Conditional Access Conditions
Microsoft's current documentation explains how Conditional Access can combine multiple signals and conditions when making access decisions.Microsoft Conditional Access Conditions
Microsoft Learn: Microsoft Entra Licensing
Current Microsoft licensing guidance covering the Microsoft Entra ID P1 requirement for Conditional Access and its availability through Microsoft 365 Business Premium.Microsoft Entra Licensing





Comments