Featured guides
Secure
Engage
Management
Reports
Configuration
Getting Started
Discover
Solutions
Audit Logs
Compliance Frameworks
Augmentt API
Secure
Purview
Teams
Intune
Conditional Access
Entra ID
Alerts
Security Posture
Defender
Creating custom policy templates
Conditional Access
Templates
Named Locations
Authentication Methods
Deploy Policies or Baselines
Conditional Access Baseline Templates (Golden Tenant)
Templates
Block Device Code Flow
CIS M365 v6 L1 - Block Device Code Sign-in Flow 5.2.2.12
CIS M365 v6 L1 - Block Legacy Authentication 5.2.2.3
CIS M365 v6 L1 - Identity Protection Sign-in Risk Policy 5.2.2.7
CIS M365 v6 L1 - Identity Protection User Risk Policy 5.2.2.6
CIS M365 v6 L1 - Managed Device Required for Authentication 5.2.2.9
CIS M365 v6 L1 - Managed Device Required to Register Security Info 5.2.2.10
CIS M365 v6 L1 - MFA for Administrative Roles 5.2.2.1
CIS M365 v6 L1 - MFA for All Users 5.2.2.2
CIS M365 v6 L1 - Sign-in Frequency and Non-Persistent Sessions for Admins 5.2.2.4
CIS M365 v6 L1 - Sign-in Frequency for Intune Enrollment 5.2.2.11
CIS M365 v6 L2 - Block Sign-in Risk Medium and High 5.2.2.8
CIS M365 v6 L2 - Idle Session Timeout for Unmanaged Devices 1.3.2
CIS M365 v6 L2 - Phishing-Resistant MFA for Administrators 5.2.2.5
NIST CSF 2.0 - Block Device Code Sign-in Flow DE.CM-09
NIST CSF 2.0 - Block Guest Access to Admin Portals PR.AA-05
NIST CSF 2.0 - Block High-Risk Sign-Ins DE.CM-09
NIST CSF 2.0 - Block High-Risk Users DE.CM-01
NIST CSF 2.0 - Block Legacy Authentication PR.PS-04
NIST CSF 2.0 - Block Unsupported Device Platforms PR.PS-01
NIST CSF 2.0 - Identity Protection Sign-in Risk Policy DE.CM-01
NIST CSF 2.0 - Identity Protection User Risk Policy DE.CM-01
NIST CSF 2.0 - Idle Session Timeout Unmanaged Devices PR.PS-01
NIST CSF 2.0 - Managed Device Required for Authentication PR.AA-05
NIST CSF 2.0 - Managed Device Required to Register Security Info PR.AA-05
NIST CSF 2.0 - MFA for Administrative Roles PR.AA-03
NIST CSF 2.0 - MFA for All Users PR.AA-03
NIST CSF 2.0 - Phishing-Resistant MFA for Admins PR.AA-02
NIST CSF 2.0 - Phishing-Resistant MFA for All Users PR.AA-02
NIST CSF 2.0 - Require Compliant Device for Azure Management PR.PS-02
NIST CSF 2.0 - Sign-in Frequency for Intune Enrollment PR.AA-01
NIST CSF 2.0 - Sign-in Frequency Non-Persistent Sessions PR.AA-01
Register MFA from Managed Devices
Require Device Compliance
Block Access for Unknown or Unsupported Device Platforms
Block High Risk Users and Sign-ins
Block Legacy Authentication
Block Risky Countries or IPs
Enforce Restrictions for Unmanaged Devices
NIST CSF 2.0 - Block Risky Countries GV.RM-01
Non-persistent Browser Session for Unmanaged Devices
Register Security Info Only From Trusted Locations
Require Anti-phishing MFA for Admins
Require Compliant or Entra Hybrid Joined Devices for Admins
Require MFA for All Users
Require New Password when User Risk is High
