Blocking Risky Countries with a Named Location
The Block Risky Countries or IPs template blocks sign-ins that come from the locations you name. It ships with no locations of its own, so nothing is in scope until you build one and point the policy at it.
This guide covers the whole job: create the deny-list location, deploy the policy against it, review the report-only results, then enforce.
What you need. The Manage permission on Secure, and a selected customer with a healthy Microsoft 365 integration.
Build the block list from the business, not from a threat feed. The most reliable version of this policy is the inverse of where the customer actually works: pick the countries they will never legitimately sign in from. Blocking a country the customer does business in generates lockouts on day one.
