Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

DE.CM-09 — Computing hardware and software integrity monitored. Blocks sign-in attempts that Entra Identity Protection classifies as medium or high risk outright — no MFA challenge, just a hard block. This is the most aggressive risk response: rather than giving a potentially compromised session a chance to satisfy MFA, it stops the attempt entirely. Best paired with the sign-in risk MFA policy to create a layered response.

What it actually does

Who it covers. Every user in the tenant, when they sign in to all cloud apps.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

When it fires. Only when Identity Protection rates the sign-in as medium and high risk.

What it enforces. Entra ID will block the sign-in outright.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

Compliance mapping

  • NIST CSF 2.0 — DE.CM-09


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.