Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

Standard MFA methods such as SMS OTP and Authenticator push notifications are vulnerable to real-time phishing and adversary-in-the-middle attacks. Phishing-resistant MFA methods - FIDO2 security keys, Windows Hello for Business, and certificate-based authentication - use cryptographic binding to the device or hardware, making them immune to these attacks. This control is required for all administrative roles and supersedes the standard MFA requirement in 5.2.2.1 for admin accounts. This policy satisfies CIS Microsoft 365 Foundations Benchmark v6.0.0 section 5.2.2.5 (L2). Requires Entra ID P2 licensing.

What it actually does

Who it covers. Users holding any of 14 administrative roles, when they sign in to all cloud apps.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

What it enforces. Entra ID will require phishing-resistant MFA strength.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

<details> <summary><strong>The 14 administrative roles in scope</strong></summary>

  • Global Administrator

  • Exchange Administrator

  • Conditional Access Administrator

  • Cloud Application Administrator

  • Authentication Administrator

  • Billing Administrator

  • Helpdesk Administrator

  • Password Administrator

  • Privileged Authentication Administrator

  • Privileged Role Administrator

  • Security Administrator

  • SharePoint Administrator

  • User Administrator

  • Global Reader

</details>

Compliance mapping

  • CIS Microsoft 365 Foundations Benchmark v6.0.0 — section 5.2.2.5 (L2)


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.