Skip to content

Investigating impossible-travel sign-in alerts

Impossible-travel alerts fire when one account signs in from two places too far apart to travel between in the time elapsed. They are useful — and notorious for false positives from VPNs, mobile networks and cloud egress. Here is how OwlSOC investigates one, separates the benign from the real, and keeps containment human-approved.

Why impossible travel is so noisy

The alert is a good idea with a high false-positive rate. A VPN or corporate proxy can place a user in another country; a phone switching from Wi-Fi to a mobile network can look like a second location; cloud services sign in on the user's behalf from data-centre IPs. Each of these trips the rule without any compromise.

The cost of that noise is real: teams start ignoring impossible-travel alerts, and the one that actually matters — a token replayed from an attacker's location — gets lost among the benign ones. The fix is not a better threshold; it is investigating each alert in context.

What OwlSOC checks

OwlSOC treats an impossible-travel alert as a question to answer, not a verdict to accept.

  • The two sign-ins: IPs, ASNs, and whether either is a known VPN, proxy, or cloud egress range.
  • The account baseline: where this user normally signs in from, and on what devices.
  • Corroborating signals: token reuse, new mail rules, MFA prompts, or failed attempts around the same time.
  • Whether the pattern is isolated to one account or shared across several.

The verdict, and the evidence behind it

OwlSOC returns a hedged verdict — likely true positive, likely false positive, or uncertain and needs review — with calibrated confidence and an evidence-linked timeline. Where the second location is a known VPN or the behaviour matches the user's baseline, it will lean towards likely false positive and show why; where a token appears replayed from an unfamiliar network with follow-on activity, it will lean the other way. Every claim cites the source log so your team can verify it, and the activity is mapped to MITRE ATT&CK.

Ambiguous cases are surfaced as needs review rather than force-fit into a verdict. For an alert type this prone to false positives, a calibrated maybe with the reasoning attached is far more useful than a confident guess.

Containment stays human-approved

If the investigation points to a real compromise, OwlSOC recommends an action — commonly revoking sessions and prompting a credential reset — but a human on your team approves it before anything runs, and only on the write scopes you have granted. Read-only by default, every action logged, reversible actions undoable.

This is a synthetic scenario for illustration; the accounts and IPs are not real customer data. On your tenant, the investigation runs on your own Sentinel and Defender sign-in signals.

Frequently asked

Why do impossible-travel alerts produce so many false positives?

Because VPNs, corporate proxies, mobile networks and cloud services can place a legitimate user in an unexpected location. Each can trip the rule without any compromise, which is why these alerts need per-alert investigation rather than a raw threshold to be useful.

How does OwlSOC tell a real impossible-travel compromise from noise?

It correlates the two sign-ins with the account's baseline, checks whether either IP is a known VPN or cloud egress range, and looks for corroborating signals like token reuse or new mail rules. It then returns a hedged verdict with the sourced evidence, leaning false positive for known-benign patterns and flagging genuine ambiguity for review.

Does OwlSOC lock the account automatically?

No. It recommends an action such as revoking sessions or prompting a reset, but a human on your team approves it before it runs, and only on the write scopes you have granted. OwlSOC is read-only by default and logs every action.

Which tools does this work with?

OwlSOC connects read-only to Microsoft Sentinel and Microsoft Defender, where sign-in and impossible-travel signals surface, and to AWS Security Hub. It investigates the alerts those tools raise.

See it on your alerts.

Start with a 30-day refundable pilot. £495, one environment, every alert investigated, a full report at week four. Read-only, live within 48 hours of access.