Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
Entra ID Identity Protection evaluates each sign-in for risk signals such as atypical travel, anonymous IP addresses, and malware-linked IPs. This policy challenges users with MFA when a sign-in is detected as medium or high risk, blocking attackers who may have stolen credentials but cannot satisfy MFA. Note: at the L2 baseline this policy is superseded by 5.2.2.8 which blocks medium and high risk sign-ins entirely rather than allowing them through with MFA. This policy satisfies CIS Microsoft 365 Foundations Benchmark v6.0.0 section 5.2.2.7 (L1). Requires Entra ID P2 licensing.
What it actually does
Who it covers. Every user in the tenant, when they sign in to all cloud apps.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
When it fires. Only when Identity Protection rates the sign-in as medium and high risk.
What it enforces. Entra ID will require multifactor authentication.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
CIS Microsoft 365 Foundations Benchmark v6.0.0 — section 5.2.2.7 (L1)
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
