Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

This policy forces re-authentication every time a user or device goes through the Intune enrollment flow. Without this control a cached session token could be used to enroll a rogue or attacker-controlled device into Intune without the legitimate user being present. Scoped specifically to the Microsoft Intune application so it does not affect day-to-day usage. This policy satisfies CIS Microsoft 365 Foundations Benchmark v6.0.0 section 5.2.2.11 (L1). Requires Microsoft Intune.

What it actually does

Who it covers. Every user in the tenant, when they sign in to the application d4ebce55-015a-49b5-a083-c84d1797ae8c.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

What it enforces. Entra ID will require multifactor authentication.

Session controls. For sessions allowed through, it forces reauthentication on every sign-in.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

Compliance mapping

  • CIS Microsoft 365 Foundations Benchmark v6.0.0 — section 5.2.2.11 (L1)


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.