One of the easiest ways to protect the data behind your web application is to identify when a user logs in from a new location and verify that they are who they say they are.
This is a relatively widely practiced process across many web applications (gmail.com, outlook.com etc.). I…

