Hi,
What you’re seeing is a fairly common scenario when compliant devices connect through mobile hotspots or international carriers, the IP routing can appear as if the device is coming from a risky or unexpected location, which then triggers the block.
A practical way to handle this is to adjust your conditional access policy to rely more heavily on device compliance and user risk signals rather than strictly on IP location. For example, you can:
- Keep your branch IP requirement for stationary office users.
- Add an exception or alternative control for compliant devices that are traveling, so they can still authenticate securely.
- Consider enabling trusted device signals (like Intune compliance and Azure AD joined status) as the primary condition, while using location as a secondary check.
This way, your field engineers won’t be locked out simply because of mobile routing, but you’ll still maintain strong security controls.
If this guidance helps resolve the issue, please hit “accept answer” so I know it was useful.
Jason