Your designer signs in to the brand account from Lisbon, your community manager from Toronto the next day, and by Wednesday someone faces a verification prompt aimed at a recovery address nobody controls. The instinct is to buy a VPN, and the wrong kind causes the outage.
What a login from a new country actually triggers
Three things get flattened into “we got locked out”. A notification arrives after a sign in that worked, as Google’s account help describes. A challenge holds the sign in until someone re-authenticates or enters a code sent to a recovery address or device. A temporary lock holds the account until that challenge passes.
The country alone rarely decides which fires. Microsoft’s Entra ID Protection documentation names the signals that do: the address and the network operator behind it, whether the device and browser are recognised from stored history, and how far apart two sign ins sit in distance and time, which it calls impossible travel. Entra’s conditional access network assignment page makes location and IP a named condition, including trusted ranges.
No named platform is described here. [EVIDENCE NEEDED: a readable help or security page from the platform itself stating what it does on a sign in from an unfamiliar location.]
Why reaching for a consumer VPN makes it worse
A consumer VPN app hands out an address from a shared pool and reconnects to whichever server is nearest or fastest, so one person can present two countries in a day without leaving their desk. Unrelated people sit on that address too, so its reputation is not yours to manage: Windscribe’s static IP page says an address shared by thousands is likelier to get blacklisted.
So the traveller’s problem is an unstable egress point, and a rotating VPN is a second one. A fixed address is a paid line item at consumer vendors too: Windscribe sells static IPs, Surfshark a dedicated IP add on.
Three ways to get a fixed egress point, and what each one changes
Tell the architectures apart by what the platform ends up seeing. On a vendor run gateway the vendor reserves an address your people connect through, and the platform sees it from every city. A self hosted gateway is your own cloud instance with a fixed address: no per seat fee, but you run the box, the patching and the 3am reboot.
A mesh network carries the trap. Tailscale’s exit node documentation is explicit that by default it routes traffic between your own devices only, so a mesh with no exit node selected changes nothing about the address a platform sees. Selecting one puts the default routes through that device. Split tunnelling decides whether the platform’s traffic uses the fixed egress at all: a dedicated IP with those domains outside the tunnel achieves nothing.
What the six vendors’ own pages say about a fixed IP
| Vendor | Entry tier as the page states it | Static or dedicated IP at that tier | Seat minimum or cap as the page states it |
|---|---|---|---|
| NordLayer | Lite, $8/user/month, pricing page. | Not on Lite. Core is $11/user/month plus $40/month for the dedicated IP server, required. The help article ties it to Core, Premium or Custom. | 5 users, stated as a minimum |
| GoodAccess | Essential, $7/user/month annually, $9 monthly, pricing page. | Included. Dedicated Static IP sits against Essential, each gateway carrying a static IP for your organisation. Extra gateways $49/month. | 5 users, stated as a minimum |
| Twingate | Starter free, Teams $5/user/month, pricing page. | Not at the entry tier. Static IPs appears only in the Custom priced Enterprise column, as an add on. The internet security overview states no fixed egress address. | Starter up to 5 users, Teams up to 100 users, caps and not minimums |
| Tailscale | Personal $0, Standard $8/user/month, pricing page. | None vendor assigned. The exit node documentation says exit nodes work on all plans, so the fixed address is whatever machine you nominate has. | Personal up to 6 users, a cap not a minimum. Standard unlimited |
| Windscribe | [EVIDENCE NEEDED: a Windscribe pricing page that serves readable content. Its pricing, plans and teams URLs returned the site’s own error page on 2026-09-08.] | Sold separately, no price on the static IP page, which needs an unlimited data account. Datacentre IPs in 10 locations, residential in 3. | Not stated |
| Surfshark | Starter, $2.49/month on the 24 month term, pricing page. | Add on from $3.75/month, dedicated IP page, any plan, location fixed at purchase. The page says 20 locations and lists 17. | Not stated, a consumer subscription |
Every price above was read on the vendor’s own page on 2026-09-08. This is not Watchdog data and is not on the re-verification schedule. followedapp is published by the team behind RecurPost.
The seat maths that actually decides it
Five people, the same brand accounts, wherever they are, using only the figures above. NordLayer needs Core, since Lite carries no dedicated IP server: five seats at $11 is $55, plus the required $40, so $95 a month. GoodAccess Essential includes the static IP gateway at the entry tier, so five seats at the $7 annual rate is $35 a month, $45 at the $9 monthly rate. The lower per seat figure is not automatically the lower bill.
Twingate drops out rather than getting an estimate, because Static IPs sits in a Custom priced tier with no number to multiply, and Windscribe because no readable pricing page resolved. Surfshark’s $3.75 buys one dedicated IP on a consumer plan, not five seats.
Self hosted swaps the vendor fee for an instance bill. DigitalOcean’s droplet pricing page, read 2026-09-08, lists a basic droplet with 1 GiB of memory and 25 GiB of SSD at $6.00 a month, and Tailscale Personal covers up to 6 users at $0, so five people could run an exit node for $6. Then the cost on no pricing page: someone owns that gateway, the patching, the seat list and the offboarding. Without that person named, $95 is cheaper than $6.
What a fixed IP does not fix
- A shared password is still a shared password, and a stable egress makes a stolen credential look more legitimate, not less. Delegating access instead of sharing it comes before this.
- It does nothing about a second factor on a device that has left the company.
- Review triggered by what the account posted, or by a report, is unrelated to where the session came from.
- One address carrying every brand account means one flagged address affects all of them at once.
- No vendor can promise a platform will not challenge a login, and none of these pages does.
- Routing the traffic changes nothing inside the browser on the same laptop: what the extensions on that laptop can already see.
Rolling it out without locking the team out
The order of operations is the whole risk. Requiring the tunnel first means every account needs re-verifying at once from a network none has seen, with the trusted sessions gone. Instead, stand up the fixed egress and, while those sessions are still valid, sign in to each account once through it and clear whatever challenge appears. Confirm it is recognised, then require the tunnel for everyone, staggered by person.
Keep one break glass path that does not depend on the gateway: a recovery address someone currently employed can open, plus a second factor that is not on one person’s phone, such as a hardware key held somewhere physical. Write it down where the team can find it at 2am, the same problem as where the playbook actually lives. Before revoking the old path, confirm every account signs in through the new egress and break glass works outside the tunnel. Removing someone from the gateway is a separate step from removing them from the social account.
FAQ
Will a business VPN stop security challenges completely?
No. It removes one cause, an egress point that moves. A new device, a new browser, a password change or a report still triggers a challenge. No vendor page read here promises otherwise.
Is using a VPN with a social account against the rules?
Check the published terms for the accounts in question before rolling anything out. No platform owned terms page on this point could be read here, so nothing is asserted either way. [EVIDENCE NEEDED: a readable terms page from the platform stating its position on VPN use for account access.]
Can I just use one team member’s home connection as the fixed point?
Usually not. Most residential connections get a dynamic address that changes when the router reconnects, which returns the instability you were removing and makes one person’s router a dependency for every brand account.
Dedicated IP or self hosted gateway for a five person team?
Ask who maintains it rather than which is cheaper. The seat maths above puts the two an order of magnitude apart on paper, and that gap closes once someone owns patching, the seat list and the 2am call.
Does the fixed IP need to be in the same country as the brand?
Stability matters more than which country, though a location matching where the business operates avoids a mismatch between the account’s stated home and its sign ins. No platform page read here documents a country requirement.
Sources
All read 2026-09-08: Entra risks, Entra network, Google alerts, NordLayer, dedicated IP, help, GoodAccess, Twingate, Twingate docs, Tailscale, exit nodes, Windscribe, Surfshark IP, Surfshark pricing, DigitalOcean.
