Description:
Verifies that Microsoft Entra Security Defaults are disabled. This check is intended for tenants that use Conditional Access — Security Defaults must be off for Conditional Access policies to apply.
Why:
Microsoft Entra Security Defaults and Conditional Access are mutually exclusive. For tenants using Conditional Access, Security Defaults should be disabled so Conditional Access policies can provide granular MFA, sign-in risk, and legacy authentication controls.
Configured: Security Defaults are disabled.
Not Configured: Security Defaults are enabled.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks: None mapped for this check.
Microsoft documentation:
IMPORTANT:
Security Defaults and Conditional Access are mutually exclusive. Use this check for tenants with Conditional Access, and the companion Security Defaults is enabled check for tenants without it. Only one of the two should be enabled in a given posture template.
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Augmentt native check. Check ID securitydefaultsdisabled (module 513)._
Sourced for this page:
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Editor note — not defined in the product: no compliance framework mapping in-app.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · Entra ID P1
