The settingWhat we hold this to
CreativeTechs minimum
None. Not asserted — see the disposition.
Benchmark position
No preventive authority asks for it: not Microsoft Secure Score, CIS, CISA or the Huntress ISPM list.
Where we differ, and why
Covered, not declined. Huntress ITDR watches sign-in location behaviourally across every managed tenant and alerts on impossible travel, which catches the anomaly without breaking a legitimate trip. If ITDR ever leaves the stack this control comes straight back and needs a real target value.
Where the switch is
n/a — not asserted.
How to verify
n/a
- Why it matters
- Cheap surface reduction if the client genuinely never works outside a region — but the ground is already held by a detective control we're keeping.
- How we check
- CA named locations. Maester MT.1011 (generic CA control).
- Fix — M365
- CA policy → block, or require step-up, from outside allowed countries.
- Fix — Google
- Context-Aware Access location rules.
- User notices
- Breaks travel, silently and confusingly, usually on a Sunday.
- Expected pushback
- High cost relative to value, and we already know people travel without telling us. No preventive authority asks for it — not Microsoft, CISA, CIS or Huntress ISPM.
- Huntress ITDR
- Full coverage, and it is active today. Huntress ITDR watches sign-in location behaviourally across every managed tenant and alerts on impossible travel and unexpected geography — including the travelling users who never tell us. A better instrument than a static country block: it catches the anomaly without breaking the legitimate trip.
- Reason on file
- Huntress ITDR watches sign-in location behaviourally. Cut because it is covered, not because location doesn't matter.
