Tier 1 · Silent19 controls · 0 met
ID
Control
State
Evidence
CTB-01
Block legacy authentication
UNKNOWN
—
CTB-02
Move per-user MFA to Conditional Access
UNKNOWN
—
CTB-03
Retire SMS, voice and email OTP as authentication methods
UNKNOWN
—
CTB-04
Block device code flow and authentication transfer
UNKNOWN
—
CTB-05
Restrict app registration and third-party consent to admins
UNKNOWN
—
CTB-06
Non-admins cannot create tenants or self-service subscriptions
UNKNOWN
—
CTB-07
Entra Password Protection with a custom banned list
UNKNOWN
—
CTB-08
One real break-glass account
UNKNOWN
—
CTB-09
Unified audit log and mailbox auditing, retention set
UNKNOWN
—
CTB-10
Block external auto-forwarding
UNKNOWN
—
CTB-11
Shared and service mailboxes: sign-in blocked
UNKNOWN
—
CTB-12
Restrict directory read for members and guests
UNKNOWN
—
CTB-23
Email authentication — SPF, DKIM and DMARC all published
UNKNOWN
—
CTB-24
Security Defaults off, Conditional Access on
UNKNOWN
—
CTB-25
Block administrators from self-service password reset
UNKNOWN
—
CTB-26
Block device platforms the client doesn't use
UNKNOWN
—
CTB-27
Restrict Entra and Azure portal access to administrators
UNKNOWN
—
CTB-28
Defender for Office policy baselines
UNKNOWN
—
CTB-29
External sender warnings — external flag and MailTips
UNKNOWN
—
Tier 2 · Runway7 controls · 0 met
ID
Control
State
Evidence
CTB-13
MFA for all users, all applications
UNKNOWN
—
CTB-14
MFA for all admin roles — no exclusions, no trusted-location bypass
UNKNOWN
—
CTB-15
Guest access restricted, guests require MFA
UNKNOWN
—
CTB-16
Admin sign-in frequency and no persistent browser session
UNKNOWN
—
CTB-17
Risk-based Conditional Access (risky sign-in, risky user)
UNKNOWN
—
CTB-30
Teams meeting and external access hygiene
UNKNOWN
—
CTB-31
SharePoint and OneDrive session hygiene
UNKNOWN
—
Tier 3 · Negotiated5 controls · 0 met
ID
Control
State
Evidence
CTB-18
Require a managed, compliant device
UNKNOWN
—
CTB-19
Phishing-resistant authentication (passkeys / FIDO2)
UNKNOWN
—
CTB-20
Separate admin accounts with no mailbox
UNKNOWN
—
CTB-21
External sharing limited to authenticated recipients
UNKNOWN
—
CTB-22
Geographic restriction on sign-in
COVERED
Huntress ITDR watches sign-in location behaviourally. Cut because it is covered, not because location doesn't matter.
