Tier 1 · SilentNo user-visible change. These go in by default; needing a conversation about one is the exception.
ID
Control
Disposition
Reason on file
Backing
CTB-01
Block legacy authentication
REQUIRED
—
3
CTB-02
Move per-user MFA to Conditional Access
REQUIRED
—
1
CTB-03
Retire SMS, voice and email OTP as authentication methods
REQUIRED
—
4
CTB-04
Block device code flow and authentication transfer
REQUIRED
Standards lag the threat; Huntress rates it High and Foundational.
1
CTB-05
Restrict app registration and third-party consent to admins
REQUIRED
—
4
CTB-06
Non-admins cannot create tenants or self-service subscriptions
REQUIRED
—
3
CTB-07
Entra Password Protection with a custom banned list
REQUIRED
—
2
CTB-08
One real break-glass account
REQUIRED
—
2
CTB-09
Unified audit log and mailbox auditing, retention set
REQUIRED
—
4
CTB-10
Block external auto-forwarding
REQUIRED
—
3
CTB-11
Shared and service mailboxes: sign-in blocked
REQUIRED
—
0
CTB-12
Restrict directory read for members and guests
REQUIRED
—
2
CTB-23
Email authentication — SPF, DKIM and DMARC all published
REQUIRED
—
3
CTB-24
Security Defaults off, Conditional Access on
CONDITIONAL
Only tenants holding Entra ID P1 — a Business Standard tenant has Security Defaults or nothing.
1
CTB-25
Block administrators from self-service password reset
REQUIRED
—
1
CTB-26
Block device platforms the client doesn't use
REQUIRED
—
1
CTB-27
Restrict Entra and Azure portal access to administrators
REQUIRED
—
1
CTB-28
Defender for Office policy baselines
CONDITIONAL
Tenants licensed for Defender for Office; verdicts pending the Maester -Service All run.
4
CTB-29
External sender warnings — external flag and MailTips
REQUIRED
—
2
Tier 2 · RunwayUsers notice these, so they need warning, a date and an enrolment path. Report-only mode first, every time.
ID
Control
Disposition
Reason on file
Backing
CTB-13
MFA for all users, all applications
REQUIRED
—
3
CTB-14
MFA for all admin roles — no exclusions, no trusted-location bypass
REQUIRED
—
3
CTB-15
Guest access restricted, guests require MFA
REQUIRED
—
1
CTB-16
Admin sign-in frequency and no persistent browser session
REQUIRED
Admins only — never apply to all users.
1
CTB-17
Risk-based Conditional Access (risky sign-in, risky user)
BLOCKED
Needs Entra ID P2. ITDR covers the detection half; only the automated response is missing.
2
CTB-30
Teams meeting and external access hygiene
UNDECIDED
—
2
CTB-31
SharePoint and OneDrive session hygiene
UNDECIDED
—
1
Tier 3 · NegotiatedEach costs a client something real. Per-client decisions, and probably per-client pricing.
ID
Control
Disposition
Reason on file
Backing
CTB-18
Require a managed, compliant device
BLOCKED
Addigy→Entra device compliance signal is a project, not a toggle. Nothing can be promised until that lands.
2
CTB-19
Phishing-resistant authentication (passkeys / FIDO2)
CONDITIONAL
Admins first; Touch ID makes this cheap on Apple hardware. Fleet-wide is a later phase.
3
CTB-20
Separate admin accounts with no mailbox
REQUIRED
—
3
CTB-21
External sharing limited to authenticated recipients
REQUIRED
—
4
CTB-22
Geographic restriction on sign-in
COVERED
Huntress ITDR watches sign-in location behaviourally. Cut because it is covered, not because location doesn't matter.
0
A control with no target value is an intention, not a measurement — every one below states the value we hold to, the benchmark position where a published figure exists, and why we differ when we do. Backing counts independent authorities only — Microsoft, CISA SCuBA, CIS M365, EIDSCA and Huntress. Maester is shown on each control but never votes: it is the measuring tool, not a standards body.
