Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

PR.PS-02 — Software maintained, replaced, and removed in a timely manner. Requires an Intune-compliant device to access the Azure Management plane (Azure Portal, Azure CLI, Azure PowerShell). The Azure management plane controls infrastructure, subscriptions, and resource configurations — access from non-compliant or unmanaged devices introduces risk of credential theft or session hijacking during privileged operations.

What it actually does

Who it covers. Every user in the tenant, when they sign in to the Windows Azure Service Management API (Azure portal, CLI and PowerShell).

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

What it enforces. Entra ID will require a device marked compliant in Intune.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

Compliance mapping

  • NIST CSF 2.0 — PR.PS-02


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.