Investigation guide
A step-by-step walkthrough of an impossible-travel sign-in alert — and how to tell account compromise from a VPN false positive.
Updated October 2026 · About 7 minutes to read
“Suspicious sign-in” and “impossible travel” alerts are among the most common identity alerts in any SOC. Many are false positives caused by VPNs or travel — but some are the first sign of an account takeover. This guide walks through a structured investigation using a Microsoft 365 example.
An alert fires for a user, Sarah, who normally signs in from Manila. The sign-in log shows:
| Time | Location | Result | Source IP |
|---|---|---|---|
| 09:42 | Manila | Success | 49.145.x.x |
| 09:51 | Manila | Success | 49.145.x.x |
| 10:03 | Moscow | Failed | 185.220.x.x |
| 10:04 | Moscow | Failed | 185.220.x.x |
| 10:05 | Moscow | Success | 185.220.x.x |
You can practice incidents like this in the Cyber Career Lab SOC Analyst simulator. Here is how to approach it.
Put every sign-in event in order and note the gaps. Two locations thousands of kilometres apart within minutes cannot both be the user physically. Failed attempts followed by a success from the new location is a classic pattern of an attacker trying, then succeeding with, a valid password.
Review the user’s sign-in history over the past weeks. Do they ever use a VPN? Do they travel? Is the device, browser and operating system familiar? A brand-new device and user agent from an unusual network raises suspicion significantly.
A successful malicious sign-in is only the start. Look at the session’s activity: new inbox rules (attackers often hide replies), mail forwarding, mass downloads from file storage, new MFA methods registered, OAuth app consents and emails sent to internal or external contacts.
If the evidence points to compromise:
If the evidence shows a benign cause, close the alert as a false or benign positive and record why, so the next analyst does not repeat the work.
The skill is not memorising which alerts are bad — it is gathering enough evidence to be confident either way.
FAQ
An alert raised when the same account signs in from two locations too far apart to travel between in the time elapsed. It can indicate a stolen password, but VPNs and inaccurate geolocation often cause false positives.
If there is reasonable evidence of compromise, yes — together with revoking sessions. If the cause is confirmed benign, document it instead. Follow your organization’s playbook.
Sign-in logs from your identity provider (such as Microsoft Entra ID), audit logs, mailbox audit logs and, where available, endpoint and network logs for the user’s devices.
Investigate it yourself
Analyze sign-in logs, collect evidence and decide whether an account was really compromised.
Start free. No experience required.