Creating an impossible-to-travel policy
The Impossible Travel feature helps to improve the security level and blocks suspicious login attempts when FortiIdentity Cloud detects an unusual login request far away from a reasonable geographical location. For example, if after a user logs in from New york and there is another login attempt from San Francisco by the same user in a period of time that is impossible to travel from New York to San Francisco, it can be blocked. FIC is able to identify suspicious sign-in attempts based on distance and time elapsed between two subsequent user sign-in attempts. Bear in mind that the user IP must be supported by FortiProducts.
To enable the Impossible Travel feature in an adaptive authentication policy:
- Click Adaptive Auth > Policies.
- Select Add Policy.
- Specify the policy name.
- For Action, select Block.
- For Filters, select Location Filter.
- Select the Impossible Travel button to enable it.
- For Schedule, select a desired schedule set.
- Click Apply.
-
Add the new policy into a profile, and be sure to select the Default action as Multi-factor Authentication. This will ensure that when the impossible travel policy is not met, the user will be prompted for multi-factor authentication and can proceed to log in. If the impossible travel condition is met, the user will be blocked based on the policy.
- Add the new profile into any application (including FortiProducts and web apps) and any realm whose users are going to log in from the specified locations.