> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/new-country-for-tenant.md).

# New Country for Tenant

Detects users successfully logging in, starting sessions, or authenticating from new locations with no operation, which may indicate an account takeover attempt.

A user will fail this check if they have any anomalous activities in the past 24 hours.

A new country is defined as one that has not been associated with a login in more than 180 days.

To reduce false positive alerts, accounts that were created less than 3 days prior to the check run are excluded. Access from a managed device will be excluded for customers with Microsoft Entra ID with Intune.<br>

**Recommended Actions**

We recommend contacting the end user to verify the origin of the actions.

**Default Check Settings:**

Anomalous activities period (hours): 24

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)

[Salesforce](/integrations/salesforce-integration.md)

[GitHub](/integrations/github.md)

[AWS](/integrations/aws.md)

<br>
