Skip to content

GeoPolicy Travel Exclusion (PIM)

Source: _imported/GeoPolicy Exclusion Guidelines/ · Applies to: all M365 tenants · Last reviewed: 2026-07

Purpose

Temporarily exclude a user from the geo-block Conditional Access policy while they travel, using Entra Privileged Identity Management (PIM) for time-boxed access.

Information required

Confirm with the client before starting:

Field Value
User UPN <user@<tenant>.onmicrosoft.com>
Travel start date <YYYY-MM-DD>
Travel return date <YYYY-MM-DD>

Steps

  1. Sign in to entra.microsoft.com.
  2. Open the exclusion group: Identity → Groups → All groups.
  3. Search for GeoPolicy-Exclusions and open it.
  4. Click Privileged Identity Management.
  5. Select Active assignments.
  6. Click + Add assignments.
  7. Set Role: Member.
  8. Select the travelling user, then click Next.
  9. Set assignment dates:
  10. Assignment type: Active
  11. Start: <travel departure date>
  12. End: <travel return date> (or next day if overnight access is required)
  13. Enter a justification note and click Assign.

Verification

  • [ ] User appears in GeoPolicy-Exclusions → Members.
  • [ ] Conditional Access policy is confirmed to exclude this group.

After completion

  • [ ] Record the exclusion in the GeoPolicy section of the webapp.
  • Do NOT manually add users directly to the group.

Notes / Gotchas

  • Access is automatically granted at the assignment start time and automatically removed at the end time — no manual cleanup needed.
  • Never add users directly to the GeoPolicy-Exclusions group; always use PIM so the membership is time-bound and auditable.