Description:
Verifies that Conditional Access Policies do not include Service Accounts.
Why:
All Conditional Access policies should be configured to exclude directory synchronization accounts. Service accounts and service principals, such as the Microsoft Entra Connect Sync Account, are non-interactive accounts that aren't tied to any particular user. They're normally used by back-end services allowing programmatic access to applications, but are also used to sign in to systems for administrative purposes. Service accounts like these should be excluded since MFA can't be completed programmatically.
Configured: Conditional Access Policies do not include Service Accounts.
Not Configured: Conditional Access Policies include Service Accounts.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks: None mapped for this check.
Microsoft documentation:
