Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

GV.RM-01 — Risk management objectives established and agreed upon. Blocks all sign-in attempts originating from countries in the tenant's "Deny List — Blocked Countries" named location. Geographic access controls reduce the attack surface by eliminating authentication attempts from regions where the organization has no users or business operations. This is especially effective against automated credential-stuffing campaigns, which commonly originate from specific high-risk geographies.

What it actually does

Who it covers. Every user in the tenant, when they sign in to all cloud apps.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

When it fires. Only when the sign-in comes from one of the Named Locations you supply when you deploy the template — the template ships with no locations of its own, so nothing is in scope until you choose them.

What it enforces. Entra ID will block the sign-in outright.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

What Augmentt asks you for at deployment

InputRequiredWhy
includeLocationsYesSelect the named location that blocks risky countries. The reference implementation uses "Deny List — Blocked Countries".

Compliance mapping

  • NIST CSF 2.0 — GV.RM-01


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.