Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
This policy works in conjunction with the idle session timeout value configured in the Microsoft 365 admin centre (Org settings - Security and privacy - Idle session timeout, recommended value 3 hours or less). The Conditional Access policy enforces that Office 365 applications honour this timeout for browser sessions on unmanaged devices. Without this policy Office 365 ignores the admin centre timeout setting. Managed devices (Intune-compliant or hybrid-joined) are explicitly excluded via device filter, so the timeout only applies to genuinely unmanaged browser sessions. This policy satisfies CIS Microsoft 365 Foundations Benchmark v6.0.0 section 1.3.2 (L2). Note: the idle timeout value itself must be configured separately in the Microsoft 365 admin centre.
What it actually does
Who it covers. Every user in the tenant, when they sign in to all Office 365 services, and only from browsers only.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
When it fires. Only when the device matches the filter device.isCompliant -eq True -or device.trustType -eq "ServerAD".
Session controls. For sessions allowed through, it hands the session to the app so SharePoint and Exchange apply limited-access (web-only) restrictions.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
CIS Microsoft 365 Foundations Benchmark v6.0.0 — section 1.3.2 (L2)
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
