Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
PR.AA-02 — Identities and credentials managed based on risk. Requires phishing-resistant authentication methods (FIDO2 security keys, Windows Hello for Business, or certificate-based MFA) for all privileged admin roles. Standard MFA methods like SMS or push notifications are vulnerable to real-time phishing proxies (e.g., Evilginx). Phishing-resistant MFA eliminates this attack surface for the accounts that matter most.
What it actually does
Who it covers. Users holding any of 14 administrative roles, when they sign in to all cloud apps.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
What it enforces. Entra ID will require phishing-resistant MFA strength.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
<details> <summary><strong>The 14 administrative roles in scope</strong></summary>
Global Administrator
Exchange Administrator
Conditional Access Administrator
Cloud Application Administrator
Authentication Administrator
Billing Administrator
Helpdesk Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
Security Administrator
SharePoint Administrator
User Administrator
Global Reader
</details>
Compliance mapping
NIST CSF 2.0 — PR.AA-02
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
