Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default
What this template is for
PR.AA-05 — Access permissions managed based on least privilege and separation of duties. Requires a managed device to register MFA methods or reset security information. This prevents an attacker who has compromised a password from registering their own MFA device on an unmanaged machine — a critical step in account takeover attacks.
What it actually does
Who it covers. Every user in the tenant.
Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.
What it enforces. Entra ID will require a Microsoft Entra hybrid joined device and require a device marked compliant in Intune — controls combined with OR.
Deployment state. Report-only.
Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.
Compliance mapping
NIST CSF 2.0 — PR.AA-05
This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.
