Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

PR.AA-05 — Access permissions managed based on least privilege and separation of duties. Requires a managed device to register MFA methods or reset security information. This prevents an attacker who has compromised a password from registering their own MFA device on an unmanaged machine — a critical step in account takeover attacks.

What it actually does

Who it covers. Every user in the tenant.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

What it enforces. Entra ID will require a Microsoft Entra hybrid joined device and require a device marked compliant in Intune — controls combined with OR.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

Compliance mapping

  • NIST CSF 2.0 — PR.AA-05


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.