@dividedwefall02@karlprosser@mattjay @FamilyMarden Have you ever created a geolocation Azure conditional access policy? It will allow a successful authentication but block it depending on the source location. The CAP runs after first factor authentication exactly as OP describes.