Template family: Conditional Access
Applies to: Microsoft Entra ID
Where to find it: Secure → Conditional Access → Templates → Augmentt Default

What this template is for

Accounts that are assigned privileged administrative roles are frequent targets of attackers. Requiring phishing-resistant multifactor authentication (MFA) on those accounts is an easy way to reduce the risk of those accounts being compromised.

https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-admin-phish-resistant-mfa

What it actually does

Who it covers. Users holding any of 15 administrative roles, when they sign in to all cloud apps.

Who is excluded. Service-provider (GDAP) guest accounts are excluded automatically, so your own technicians keep access if the policy misfires.

What it enforces. Entra ID will require phishing-resistant MFA strength.

Session controls. For sessions allowed through, it forces reauthentication on every sign-in.

Deployment state. Report-only.

Augmentt deploys this template in report-only mode. Entra ID evaluates every sign-in and records what would have happened in the sign-in logs, but nothing is blocked or challenged until you switch the policy to On. Review the report-only results before enforcing.

<details> <summary><strong>The 15 administrative roles in scope</strong></summary>

  • Global Administrator

  • Security Administrator

  • SharePoint Administrator

  • Exchange Administrator

  • Conditional Access Administrator

  • Helpdesk Administrator

  • Billing Administrator

  • User Administrator

  • Authentication Administrator

  • Application Administrator

  • Cloud Application Administrator

  • Password Administrator

  • Privileged Authentication Administrator

  • Privileged Role Administrator

  • Hybrid Identity Administrator

</details>

What Augmentt asks you for at deployment

InputRequiredWhy
excludeUsersNoBreak glass account may be excluded.

This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.