Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States

Essential Eight Compliance Guide for Australian Businesses

 ·  By

The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre. It exists because a small number of controls, applied consistently, stop the overwhelming majority of intrusions Australian organisations actually experience. This guide explains what each strategy requires, how the maturity levels work, and how to meet them with the Microsoft 365 stack most Australian businesses already own.

What the Essential Eight actually is

The ASD publishes hundreds of security controls. The Essential Eight is the prioritised subset judged most effective as a baseline for any organisation: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.

Each strategy is graded across three maturity levels. Level 1 defends against opportunistic attackers using publicly available tooling. Level 2 defends against adversaries prepared to invest more effort, typically through phishing and credential theft. Level 3 addresses skilled, well-resourced attackers using custom exploits. The framework is deliberately incremental — the goal is to meet all eight strategies at one level before advancing, rather than reaching Level 3 on two controls and Level 0 on the rest.

Most Australian small and medium businesses should target Maturity Level 1 as a genuine baseline. Government suppliers, defence contractors under the Defence Industry Security Program, critical infrastructure operators, and businesses handling health or financial data are typically expected to demonstrate Level 2.

The eight strategies and what they require

Application control. Only approved software executes on endpoints. At Level 1 this means blocking execution of unapproved executables, scripts and installers in user-writable locations. Microsoft Defender Application Control or Intune-managed AppLocker delivers this without third-party tooling.

Patch applications. Internet-facing applications — browsers, email clients, Office, PDF readers — need critical patches within 48 hours. Other applications within two weeks. Unsupported software must be removed rather than tolerated.

Configure Microsoft Office macro settings. Macros from the internet are blocked, and only macros from trusted locations or with a trusted digital signature run. This is a single Intune administrative template for most tenants.

User application hardening. Web browsers do not process Java or Flash content, browser advertising is blocked, and unnecessary Office and PDF features are disabled. Microsoft Edge security baselines provide a defensible starting policy.

Restrict administrative privileges. Privileged access is requested, validated, time-limited, and separated from day-to-day accounts. Entra ID Privileged Identity Management handles just-in-time elevation for Global Administrator and other high-risk roles.

Patch operating systems. Internet-facing operating systems patched within 48 hours, others within two weeks, with unsupported versions replaced. Intune and Windows Autopatch cover this with reporting through Defender for Endpoint.

Multi-factor authentication. MFA on all internet-facing services and privileged accounts, moving toward phishing-resistant methods at higher maturity levels. Conditional Access with number matching, plus a block on legacy authentication, is the practical implementation.

Regular backups. Daily backups of important data, software and configuration, retained according to business needs, stored so that they cannot be modified or deleted by the accounts that created them, and tested through actual restores.

Server racks in a data centre supporting Essential Eight patching and backup controls

Photo by Fotos on Unsplash

Why it matters commercially

Beyond the security case, the Essential Eight has become a commercial gate. Cyber insurers routinely ask about multi-factor authentication, privileged access and backup testing before quoting, and price accordingly. Enterprise and government buyers increasingly ask suppliers to evidence maturity as part of supply chain risk assessment. Company directors also carry an expectation under general duties to manage cyber risk as part of overall business risk — a recognised framework gives boards something concrete to measure and report against. Our advisory team helps boards translate these obligations into a funded roadmap, and for finance-led operations we pair it with business-central-implementation work so security and ERP change land together.

For distributed operations — mining and resources sites, construction projects, multi-venue hospitality — the framework matters operationally as well. Attacks on these businesses target continuity, not just data, and the controls that keep an environment recoverable are the same ones the Essential Eight prioritises.

Getting to Maturity Level 1

Level 1 is achievable for most Microsoft 365 environments in a matter of weeks. A workable sequence:

  1. Baseline the environment. Document users, devices, administrative accounts, internet-facing systems, and current Microsoft 365 configuration. Score honestly against each of the eight strategies.
  2. Fix identity first. Enforce MFA for every user through Conditional Access, block legacy authentication, and remove standing Global Administrator assignments.
  3. Bring devices under management. Enrol endpoints in Intune, apply update rings for operating systems and Microsoft 365 Apps, and deploy the Office macro and browser hardening baselines.
  4. Prove the backups. Confirm daily backups of Microsoft 365 data and server workloads, ensure they are immutable or otherwise isolated from production credentials, and run a documented restore test.
  5. Collect evidence. Export Conditional Access policies, Intune configuration profiles, Defender vulnerability reports, and restore test results. Evidence is what an assessment turns on, not intent.

Application control is usually the last control to land, because it needs a real inventory of business software and a pilot group before broad enforcement. Where AI tooling is part of the environment, apply the same discipline to it: platforms such as Curki.ai and Glue Sky should be inventoried, access-controlled and covered by the same identity and logging standards as any other business application.

Moving to Level 2 and Level 3

Level 2 introduces stricter administrative controls: privileged accounts cannot browse the web or access email, administrative activity is logged centrally, and multi-factor authentication becomes phishing-resistant. Patching windows tighten and application control moves from user-writable locations to broader enforcement.

Level 3 requires dedicated hardened administrative workstations, comprehensive event log collection and monitoring, and automated response to detected activity. At this point most organisations need continuous monitoring capability, either in-house or through a security operations centre.

Reviewing security and compliance reporting on a tablet

Photo by Dan Nelson on Unsplash

Common failure points

The gaps that show up most often in assessments are consistent. Multi-factor authentication is enabled but exempts service accounts, shared mailboxes or executives. Operating systems are patched but third-party applications drift. Backups run but have never been restored. Administrative privileges are granted permanently rather than just in time. Configuration exists but is undocumented, so it cannot be evidenced.

The other recurring issue is drift. Compliance achieved in March erodes by September as staff change, new applications are introduced, and exceptions accumulate. Quarterly internal review against each of the eight strategies, with an independent assessment annually, keeps the posture honest.

Where to start

If you are preparing for a formal assessment, our Essential Eight audit preparation guide sets out the evidence you will need to collect. If you want an objective read on where your environment currently sits, the Essential Baseline audit scores a Microsoft 365 tenant against all eight strategies and returns a prioritised remediation plan.

Book Your Cyber Security Audit Today

Mycelium 365 is a Microsoft Solutions Partner delivering Essential Eight aligned security across Microsoft 365, Entra, Intune and Defender for businesses in Australia and New Zealand. You can read our story, and see how we give back through greener fields.


Image credits: Photography by Fotos and Dan Nelson on Unsplash.

Frequently asked questions

What are the three Essential Eight maturity levels?

Maturity Level 1 defends against opportunistic attackers using widely available tools. Level 2 targets adversaries willing to invest more time and effort, typically using phishing and credential theft. Level 3 addresses skilled, well-resourced attackers using custom tooling. Most Australian SMBs should target Level 1 and lift the identity and backup controls toward Level 2.

Is Essential Eight compliance mandatory for Australian businesses?

It is not legally mandated for all private companies. It is required for many Commonwealth entities, government contractors, defence suppliers under DISP, and critical infrastructure operators. It is also increasingly used by cyber insurers and enterprise clients as a supply chain requirement, so most growing businesses encounter it eventually.

How quickly do patches need to be applied?

For internet-facing services and applications, critical patches must be applied within 48 hours of release. Other applications and operating systems generally need patching within two weeks at Maturity Level 1, tightening at higher levels. Unsupported software must be removed.

Does the Essential Eight apply to Microsoft 365?

Yes. Multi-factor authentication, restricting administrative privileges, regular backups, and application hardening all apply directly to Microsoft 365. Entra ID Conditional Access, Intune, Defender, and Microsoft 365 Backup cover every control at Maturity Level 1 and most at Level 2.

How long does Essential Eight implementation take?

For a Microsoft 365 environment with reasonable hygiene, six to twelve weeks is typical: two weeks to baseline current maturity, four to eight weeks of remediation, and one to two weeks collecting evidence before an assessment.