So, I have had a users mailbox get compromised. Obviously a password they used in too many places.
Anyway, I have been thinking about a way to help mitigate this problem.
At the Server / Domain / User level. Have a setting that states.. User may only authenticate from X unique IP addresses before being throttled or shut down.
Also, I believe we know the home country of the user based on a zip code. I am pretty sure this is captured somewhere or we could configure it. But maybe we could even say, Do not allow user to connect from any country other than their home country. Or allow a list of countries a user could authenticate from. It would be great if the user could configure that too. They cannot shut off their home country, but they could allow themselves to connect from another country if needed.
Any thoughts? Could this idea be improved?