CreativeTechsBaseline
tenant security posture
Control library · v0.9 draft

The CreativeTechs Baseline

What we hold every managed tenant to, and why. Each control carries a disposition — and everything except Required carries a written reason, so a decision made once doesn’t get re-litigated a year later.

26
In the baseline
1
Covered elsewhere
2
Blocked
0
Declined
2
Undecided
31/31
Have a target value
24
Carry a divergence note
Tier 1 · SilentNo user-visible change. These go in by default; needing a conversation about one is the exception.
ID
Control
Disposition
Reason on file
Backing
CTB-01
Block legacy authentication
REQUIRED
3
CTB-02
Move per-user MFA to Conditional Access
REQUIRED
1
CTB-03
Retire SMS, voice and email OTP as authentication methods
REQUIRED
4
CTB-04
Block device code flow and authentication transfer
REQUIRED
Standards lag the threat; Huntress rates it High and Foundational.
1
CTB-05
Restrict app registration and third-party consent to admins
REQUIRED
4
CTB-06
Non-admins cannot create tenants or self-service subscriptions
REQUIRED
3
CTB-07
Entra Password Protection with a custom banned list
REQUIRED
2
CTB-08
One real break-glass account
REQUIRED
2
CTB-09
Unified audit log and mailbox auditing, retention set
REQUIRED
4
CTB-10
Block external auto-forwarding
REQUIRED
3
CTB-11
Shared and service mailboxes: sign-in blocked
REQUIRED
0
CTB-12
Restrict directory read for members and guests
REQUIRED
2
CTB-23
Email authentication — SPF, DKIM and DMARC all published
REQUIRED
3
CTB-24
Security Defaults off, Conditional Access on
CONDITIONAL
Only tenants holding Entra ID P1 — a Business Standard tenant has Security Defaults or nothing.
1
CTB-25
Block administrators from self-service password reset
REQUIRED
1
CTB-26
Block device platforms the client doesn't use
REQUIRED
1
CTB-27
Restrict Entra and Azure portal access to administrators
REQUIRED
1
CTB-28
Defender for Office policy baselines
CONDITIONAL
Tenants licensed for Defender for Office; verdicts pending the Maester -Service All run.
4
CTB-29
External sender warnings — external flag and MailTips
REQUIRED
2

A control with no target value is an intention, not a measurement — every one below states the value we hold to, the benchmark position where a published figure exists, and why we differ when we do. Backing counts independent authorities only — Microsoft, CISA SCuBA, CIS M365, EIDSCA and Huntress. Maester is shown on each control but never votes: it is the measuring tool, not a standards body.