Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
This policy enables for MFA for all users with exception for breakglass account or groups.
Requiring multi-factor authentication (MFA) for all users helps protect devices and data that are accessible to these users. Adding more authentication methods, such as a phone token or a badge, increases the level of protection in the the event that one factor is compromised.
What it actually does
Who it covers. Every user in the tenant, when they sign in to all cloud apps.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
What it enforces. Entra ID will require multifactor authentication.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
What Augmentt asks you for at deployment
| Input | Required | Why |
excludeUsers | No | Exclude breakglass account |
excludeGroups | No | Exclude group containing Service Accounts for legacy apps if applicable to this tenant. |
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
