Tier 1 · Silent19 controls · 4 met
ID
Control
State
Evidence
CTB-01
Block legacy authentication
MET
1 of 1 score controls complete.
CTB-02
Move per-user MFA to Conditional Access
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-03
Retire SMS, voice and email OTP as authentication methods
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-04
Block device code flow and authentication transfer
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-05
Restrict app registration and third-party consent to admins
MET
1 of 1 score controls complete.
CTB-06
Non-admins cannot create tenants or self-service subscriptions
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-07
Entra Password Protection with a custom banned list
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-08
One real break-glass account
MET
1 of 1 score controls complete.
CTB-09
Unified audit log and mailbox auditing, retention set
NOT MET
1 of 1 score controls at zero.
CTB-10
Block external auto-forwarding
NOT MET
2 of 2 score controls at zero.
CTB-11
Shared and service mailboxes: sign-in blocked
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-12
Restrict directory read for members and guests
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-23
Email authentication — SPF, DKIM and DMARC all published
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-24
Security Defaults off, Conditional Access on
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-25
Block administrators from self-service password reset
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-26
Block device platforms the client doesn't use
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-27
Restrict Entra and Azure portal access to administrators
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-28
Defender for Office policy baselines
MET
5 of 5 score controls complete.
CTB-29
External sender warnings — external flag and MailTips
UNKNOWN
No Secure Score evidence — awaiting Maester.
Tier 2 · Runway7 controls · 2 met
ID
Control
State
Evidence
CTB-13
MFA for all users, all applications
MET
1 of 1 score controls complete.
CTB-14
MFA for all admin roles — no exclusions, no trusted-location bypass
MET
1 of 1 score controls complete.
CTB-15
Guest access restricted, guests require MFA
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-16
Admin sign-in frequency and no persistent browser session
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-17
Risk-based Conditional Access (risky sign-in, risky user)
NOT MET
2 of 2 score controls at zero.
CTB-30
Teams meeting and external access hygiene
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-31
SharePoint and OneDrive session hygiene
UNKNOWN
No Secure Score evidence — awaiting Maester.
Tier 3 · Negotiated5 controls · 1 met
ID
Control
State
Evidence
CTB-18
Require a managed, compliant device
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-19
Phishing-resistant authentication (passkeys / FIDO2)
UNKNOWN
No Secure Score evidence — awaiting Maester.
CTB-20
Separate admin accounts with no mailbox
MET
1 of 1 score controls complete.
CTB-21
External sharing limited to authenticated recipients
NOT MET
2 of 2 score controls at zero.
CTB-22
Geographic restriction on sign-in
COVERED
Huntress ITDR watches sign-in location behaviourally. Cut because it is covered, not because location doesn't matter.
