Custom baselines: adapting the audit to your context
No generic framework fits every organisation perfectly. Some controls do not apply to you; others, secondary in the standard, are critical in your context. Custom baselines let you shape the audit around your reality instead of a one-size-fits-all standard.
What a baseline is
A baseline is a tailored version of the audit framework. You start from the 283 standard controls and then adjust two things: which controls apply, and how much each one matters. The compliance score is then computed against your baseline rather than a generic default.
Two adjustments
Exclude what does not apply
If you do not use a particular service, or a control is genuinely out of scope for your environment, exclude it. This prevents dozens of irrelevant "non-compliant" results that would otherwise drag down your score and bury the findings that matter.
Adjust criticality
Reclassify a control as level 1 or level 2 based on your own risk priorities. A control the standard treats as hardening might be business-critical for you — raise its weight so the score reflects that.
The result: a score that reflects your real requirements, not a generic standard — and a report that an auditor can see was applied deliberately, because the baseline is documented.
Global vs client-specific baselines
A baseline can be global — reusable across all your audits — or client-specific. The latter is ideal for service providers and MSPs who audit several organisations with different requirements. You maintain one baseline per client, each reflecting that client's scope and risk appetite.
Traceability
The applied baseline is recorded in your reports. That means anyone reading the report can see exactly which controls were in scope and how they were weighted — essential for defending the result and for repeating the audit consistently over time.
A practical workflow
- Run a first audit with the standard framework to see the full picture.
- Identify controls that are genuinely out of scope and exclude them.
- Raise the criticality of controls that are business-critical for you.
- Save the baseline (global or per client) and re-audit against it.
- Track the score over time — now measured against your real requirements.
Audit your Microsoft environment
Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.
Download the free demo