Enterprise security has spent the best part of two decades answering one question: who are you?
It’s a question that sits at the heart of Identity and Access Management (IAM), Multi-Factor Authentication (MFA), Privileged Access Management (PAM) and, more recently, Zero Trust architectures. Before any user is granted access to sensitive systems, organisations want to establish that they are who they claim to be. Every improvement in authentication has represented a further step towards answering that question with confidence.
The approach is, and has been, entirely rational. But attackers have adapted.
Today’s cyber criminals rarely need to defeat authentication in the traditional sense. They steal credentials through phishing, intercept authenticated sessions using adversary-in-the-middle attacks, harvest tokens from compromised devices, or purchase credentials that have already been exposed elsewhere. Increasingly, they don’t arrive as anonymous intruders. They arrive looking exactly like legitimate users.
Successful authentication isn’t the end of the story, it’s the start.
Identity isn’t everything
A successful login confirms that a user has satisfied your authentication requirements, but it doesn’t necessarily prove that the request itself is legitimate.
What it doesn’t tell you is whether the request itself makes sense.
Should a contractor be attempting to access privileged systems from a country where your organisation has no presence? Why is an employee who normally works from your London office authenticating from Australia in the early hours of the morning? How has the same account apparently travelled between two continents within an hour?
Identity can’t answer those questions exactly because identity establishes only who a user claims to be and says nothing about the circumstances surrounding the request.
That dual question of who are you? and where are you? becomes increasingly important as organisations embrace hybrid working, cloud services and globally distributed workforces. The traditional network perimeter has largely disappeared, making contextual signals far more valuable than they once were.
This is where geofencing plays a critical role.
More than a geographical boundary
Geofencing is often viewed simply as a way of blocking or allowing access from specific countries. But treating it purely as a geographical control underestimates its value in determining whether an authentication request fits a pattern of legitimate behaviour.
Modern identity platforms such as Microsoft Entra and Okta already recognise this through Conditional Access policies. Rather than relying solely on credentials, they evaluate multiple signals before deciding how a login should proceed. Location can be assessed alongside device health, user risk, previous activity and session context to determine whether access should be granted immediately, challenged with additional authentication or blocked altogether.
The objective isn’t to assume that every unfamiliar location represents malicious activity, but to understand when something deserves further scrutiny. A successful login from a trusted office network during normal business hours carries a very different level of confidence from an identical login originating from an unexpected region, particularly when combined with other indicators that suggest elevated risk.
Context creates confidence
The real strength of geofencing is in its integration into the wider security ecosystem.
Combined with Security Information and Event Management (SIEM) platforms, security teams can correlate geographic information with impossible travel events, unusual login times, privilege escalation attempts, unmanaged devices and behavioural analytics to build a much clearer picture of what’s actually happening.
Instead of treating authentication as a binary decision, organisations begin evaluating confidence.
Not every location can be trusted
Like every security control, geofencing has limitations.
VPNs can disguise a user’s true location. Cloud infrastructure can make legitimate users appear to be operating from unexpected regions. IP-based geolocation isn’t always precise, particularly across mobile networks, and globally distributed organisations often need to accommodate travelling executives, contractors and hybrid employees whose locations change regularly.
Authentication tokens introduce another complication, with some applications continuing to operate without repeatedly evaluating location throughout a session. This isn’t a reason to dismiss geofencing, but a reminder that no individual security signal can be trusted in isolation.
Asking better questions
For most organisations, implementing geofencing wouldn’t require a fundamental redesign of their security architecture.
Platforms such as Microsoft Entra and Okta already support location-aware Conditional Access policies that can be applied selectively to privileged accounts, sensitive applications or high-risk regions. When combined with SIEM correlation and existing behavioural analytics, location can function straightforwardly as a mechanism for reducing uncertainty, rather than a precious addition to internal systems.
Attackers will always be a threat, but asking better questions around access will mitigate the risks they pose.
Enterprise security has spent years becoming exceptionally good at answering one question. The most defensible companies are now asking follow-ups, not simply “who are you?”, but “where are you?” and “why are you here in the first place?”



