Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
PR.AA-05 — Access permissions managed based on least privilege and separation of duties. Blocks all guest and external user types from accessing Microsoft Admin Portals (Azure Portal, M365 Admin Center, Exchange Admin Center, etc.). Guest accounts should never need administrative access to your tenant; blocking this by policy eliminates a common misconfiguration risk. Note: this policy targets guest user types only — Service Provider Users (GDAP partners) are not included in the scope and are unaffected.
What it actually does
Who it covers. The users you select at deployment, when they sign in to the application MicrosoftAdminPortals.
What it enforces. Entra ID will block the sign-in outright.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
NIST CSF 2.0 — PR.AA-05
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
