GeoPolicy Travel Exclusion (PIM)¶
Source:
_imported/GeoPolicy Exclusion Guidelines/· Applies to: all M365 tenants · Last reviewed: 2026-07
Purpose¶
Temporarily exclude a user from the geo-block Conditional Access policy while they travel, using Entra Privileged Identity Management (PIM) for time-boxed access.
Information required¶
Confirm with the client before starting:
| Field | Value |
|---|---|
| User UPN | <user@<tenant>.onmicrosoft.com> |
| Travel start date | <YYYY-MM-DD> |
| Travel return date | <YYYY-MM-DD> |
Steps¶
- Sign in to entra.microsoft.com.
- Open the exclusion group: Identity → Groups → All groups.
- Search for
GeoPolicy-Exclusionsand open it. - Click Privileged Identity Management.
- Select Active assignments.
- Click + Add assignments.
- Set Role:
Member. - Select the travelling user, then click Next.
- Set assignment dates:
- Assignment type:
Active - Start:
<travel departure date> - End:
<travel return date>(or next day if overnight access is required) - Enter a justification note and click Assign.
Verification¶
- [ ] User appears in GeoPolicy-Exclusions → Members.
- [ ] Conditional Access policy is confirmed to exclude this group.
After completion¶
- [ ] Record the exclusion in the GeoPolicy section of the webapp.
- Do NOT manually add users directly to the group.
Notes / Gotchas¶
- Access is automatically granted at the assignment start time and automatically removed at the end time — no manual cleanup needed.
- Never add users directly to the GeoPolicy-Exclusions group; always use PIM so the membership is time-bound and auditable.