Description:

Verifies that Conditional Access Policies do not include Service Accounts.

Why:

All Conditional Access policies should be configured to exclude directory synchronization accounts. Service accounts and service principals, such as the Microsoft Entra Connect Sync Account, are non-interactive accounts that aren't tied to any particular user. They're normally used by back-end services allowing programmatic access to applications, but are also used to sign in to systems for administrative purposes. Service accounts like these should be excluded since MFA can't be completed programmatically.

Configured: Conditional Access Policies do not include Service Accounts.

Not Configured: Conditional Access Policies include Service Accounts.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Requires Premium (P1) licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks: None mapped for this check.

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID MT.1020 (module 1006)._

Sourced for this page:

  • Category — Maester test catalog (maester.dev/docs/tests) — listed under "CA"

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.

Editor note — not defined in the product: no compliance framework mapping in-app.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Entra ID P1