Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
PR.AA-02 — Identities and credentials managed based on risk. Extends phishing-resistant authentication (FIDO2, WHfB, x509 certificates) to all users across all cloud applications. As adversary-in-the-middle (AiTM) phishing kits become widely available, even non-admin accounts need protection beyond traditional MFA. This policy future-proofs the tenant's authentication posture.
What it actually does
Who it covers. Every user in the tenant, when they sign in to all cloud apps.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
What it enforces. Entra ID will require phishing-resistant MFA strength.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
NIST CSF 2.0 — PR.AA-02
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
