Securing internet traffic from devices with identity-aware web filtering and threat protection
Create a Conditional Access policy that blocks the country/region, then exclude a group that contains only that user.
Recommended approach:
- In Microsoft Entra admin center, go to Entra ID > Conditional Access > Named locations.
- Create a Countries location for the blocked country/region.
- Create or use a cloud security group for exceptions.
- Add the single user to that group.
- In the Conditional Access policy that blocks that country/region, use that group as an exclusion.
- Test the policy first with report-only mode and the What If tool before enabling it broadly.
Important points:
- Excluding users from a block-by-location policy is a documented pattern for users who still have a valid reason to sign in from blocked countries/regions, such as work travel.
- To keep the exception controlled, use an access review on the exclusion group so membership is reviewed regularly. A recommended setup is recurring review, user self-attestation, and automatic removal if the user does not respond.
- Exclude emergency access / break-glass accounts from location-based block policies to avoid tenant lockout.
- Block access is a powerful control and should be tested carefully to avoid unintended lockouts.
If the goal is only one user, keeping that user as the only member of the exclusion group is the simplest supported design.
