Many organisations invest in identity and access management, then leave the front door open to anyone with valid credentials, regardless of where they’re logging in from. Daniel Shone at Apex Computing explains the importance of geofencing

Businesses invest huge sums in identity and access management (IAM). They deploy multi-factor authentication and invest in privileged access management and SIEM platforms. But the most obvious question is frequently being overlooked: where is a user logging in from? All too often, a contractor authenticating from Lagos at 2 am will receive the same access as a CISO logging in from the London office at 9 am. If the credentials are valid and the authentication requirements are met, the system sees no reason to differentiate between them. And that’s where problems develop.
Geofencing is often viewed as a physical security tool, but it can also serve as an access control mechanism. It adds location as a security signal, allowing organisations to make more informed decisions about who should have access, under what circumstances, and from where. So, why are so few businesses taking advantage of it?
Traditional IAM systems answer the question, "Who are you?" Geofencing helps answer the equally important, "Where are you?" And this matters because although identity-based security is important, credentials can be stolen, session tokens can be hijacked, and attackers can complete authentication through phishing or adversary-in-the-middle attacks. Once authentication succeeds, it’s game on.
There are conditional access platforms that recognise this. Microsoft, for example, allows businesses to evaluate location alongside other signals, such as device health, user risk, and session context to determine whether access should be granted. So, if an employee who normally works in London suddenly attempts to access sensitive systems from a country the business doesn’t operate in, additional scrutiny will be triggered.
The lack of uptake of geofencing is all the more surprising because it fits in with most security stacks so well. It can be implemented through the IAM layer itself, with platforms like Microsoft Entra and Okta, which already support location policies and can restrict, challenge, or monitor access based on geography or trusted network ranges. But it’s when geofencing is integrated with SIEM platforms that location-based alerts can be correlated with other indicators, including unusual login times, impossible travel events, privilege escalation attempts, or unusual device behaviour.
Instead of generating an alert simply because a user logged in successfully, security teams gain context. And a successful login from a trusted office network looks very different from one from an unusual place at a strange time.
That said, geofencing isn’t infallible. If a VPN is in use in a trusted country, geographic controls become less effective. Cloud infrastructure can create similar problems, with work and users appearing to originate in places that do not reflect reality. And when you add in remote and hybrid workers, things become even more complicated. A strict country-based policy may work if your entire team is based in-house within the UK, but when you work with contractors or have executives who travel widely, things become more difficult.
Another factor to be aware of is that location data is not always perfectly accurate. There can be inconsistencies in IP-based geolocation, particularly when mobile networks and hotspots are involved. And then there’s the practical issue of authentication tokens. Some applications continue operating using previously issued tokens, meaning location-based controls may not always be evaluated as frequently as expected.
While these are obvious limitations to be aware of when deploying geofencing, no security system is perfect. The aim is risk reduction, and geofencing does that.
Effective geofencing usually starts with identifying both trusted locations and high-risk regions for your business, allowing access requests from trusted networks to be granted quickly, and requests from unexpected places to trigger further authentication or investigation.
Next, you’d look at applying location-based controls selectively. Some accounts are more vulnerable and pose higher risk than others. So, it’s worthwhile enforcing strong location security on administrative accounts and privileged users, for example.
And then you need to bring in context. Location can provide so much more information when combined with device health, behavioural analytics, risk scoring, and user activity patterns.
And perhaps most importantly, businesses need to treat geofencing as part of access control, not merely as a network security feature.
For years, enterprise security has focused on identity. And that’s entirely understandable. But it has also created a blind spot that convinces systems and people that identity is enough. And that’s where problems develop.
Geofencing will not stop every attack. The scammers are becoming increasingly sophisticated. But location provides incredibly useful context for security teams to work around, helping them to determine not just who is accessing their systems, but whether they should be there in the first place.
Daniel Shone is the founder of Apex Computing, an award‑winning Managed Service Provider
Main image courtesy of iStockPhoto.com and Natee127
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543