Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
Requiring users to register MFA methods and security information from a managed device prevents attackers who have compromised credentials from registering their own MFA methods remotely. Without this control, an attacker with stolen credentials could register a new authenticator and take over the account before the legitimate user notices. This policy satisfies CIS Microsoft 365 Foundations Benchmark v6.0.0 section 5.2.2.10 (L1). Requires Microsoft Intune.
What it actually does
Who it covers. Every user in the tenant.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
What it enforces. Entra ID will require a Microsoft Entra hybrid joined device and require a device marked compliant in Intune — controls combined with OR.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
CIS Microsoft 365 Foundations Benchmark v6.0.0 — section 5.2.2.10 (L1)
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
