# NOT_RUN: conceptual specification, not a Microsoft Graph payload.
Context: Privileged Infrastructure v1
Publish to apps: Yes
Users: Platform Engineers (pilot scope first)
Target resources: Authentication context
Grant: Require ALL selected controls
  - Require phishing-resistant MFA authentication strength
  - Require device to be marked as compliant
Session: Evaluate an appropriate sign-in frequency
Risk: Review applicable organization-wide risk policies
Exclusions: Explicitly reviewed emergency identities
Rollout: Report-only -> enforced pilot -> reviewed expansion
