Understand the displayed fields
The regular IP Address or Reported IP elsewhere in the device details may be an internal network address. The External IP in the IP location section is the address used for location lookup.
Why results can differ from the device location
An external IP describes a network connection, not a device sensor. Common reasons for a different or broad result include:Office NAT
Many devices at one office can share the same external IP and therefore share one approximate location.
VPN or secure gateway
The result may identify the VPN or security service exit point instead of the device.
Mobile networks
Carrier traffic can exit far from the device and may cover a large service area.
ISP address allocation
Providers can register or route address ranges through a nearby city or regional hub.
Lookup reuse and refresh timing
MSPortal reuses recent results for the same public IP so office devices sharing one internet connection do not create duplicate lookups.
Automatic background enrichment is disabled by default and can be enabled centrally for your environment. When enabled, eligible external IPs are checked daily within a configured lookup limit. Opening a device alone displays the available cached result; it does not force a new provider lookup. The displayed Last checked value shows the age of the current location result.
Privacy and access
- MSPortal sends the valid public IP to MaxMind for the lookup, without device names or internal IPs; it does not request device GPS data.
- Private, reserved, malformed, and network-range addresses are rejected before lookup.
- MSPortal stores normalized IP-location fields rather than retaining the provider’s complete raw response.
- Location access follows the same tenant, company, and device permissions as the device itself.
- Users who can manage devices can request a forced refresh; other authorized device viewers can view available results.
- Open map opens an external OpenStreetMap page with the approximate coordinates in its URL, without the device name or IP address.
Recommended uses
Confirm expected offices
Check whether a device’s connection appears near a known client office.
Investigate unexpected regions
Use a surprising country or region as a reason to review VPN, identity, and RMM telemetry.
Recognize shared egress
Identify devices that appear together because they share an office firewall or gateway.
Support remote-work context
Add approximate network context while troubleshooting a remote device.
Best practices
- Treat the location as approximate, especially for VPN, mobile, satellite, and cloud-hosted connections.
- Review IP observed before acting on a result; an older IP may no longer represent the device’s current connection.
- Corroborate unexpected locations with sign-in logs, RMM activity, VPN records, and the device’s assigned company or site.
- Avoid repeated manual refreshes. A fresh lookup cannot make an inherently imprecise IP range exact.
Frequently asked questions
Do portal users need a MaxMind API key?
Do portal users need a MaxMind API key?
No. The location provider is configured centrally for the MSPortal service and has no portal-level API key setting. Authorized users run lookups from the device details without entering provider credentials.
Does MSPortal track the device continuously?
Does MSPortal track the device continuously?
No. MSPortal looks up an external IP reported during device synchronization. It does not receive live GPS coordinates or continuously track movement.
Why do several devices show the same location?
Why do several devices show the same location?
They likely share the same office firewall, VPN gateway, ISP connection, or other internet exit point. This is expected for devices behind network address translation.
Why is there no city or accuracy radius?
Why is there no city or accuracy radius?
Some address ranges only support a broader regional or country result. MSPortal shows the fields the provider can return instead of inventing more precise information.