Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
DE.CM-01 — Networks and network services monitored for anomalous activity. When Entra Identity Protection flags a user account as high-risk (leaked credentials, impossible travel, malware-linked IP, etc.), this policy forces the user to satisfy MFA and change their password before access is restored. This is a self-healing control — compromised accounts are automatically remediated without waiting for admin intervention.
What it actually does
Who it covers. Every user in the tenant, when they sign in to all cloud apps.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
When it fires. Only when Entra ID Identity Protection rates the user as high risk.
What it enforces. Entra ID will force a password change and require multifactor authentication strength — controls combined with AND.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
NIST CSF 2.0 — DE.CM-01
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
