Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

Reduce risk of an adversary using stolen user credentials and then registering their own MFA device to access the tenant by requiring a managed device provisioned and controlled by the agency to perform registration actions. This prevents the adversary from using their own unmanaged device to perform the registration.

What it actually does

Who it covers. Every user in the tenant.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

When it fires. Only when the device platform is all.

What it enforces. Entra ID will require a device marked compliant in Intune and require a Microsoft Entra hybrid joined device — controls combined with OR.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.