Case study
How a WA Mining and Resources Firm Hardened Identity and Endpoints with Microsoft Security
A Perth-headquartered mining and resources firm with FIFO crews and remote exploration sites needed to strengthen its security posture to meet board, insurer and joint-venture partner expectations. Mycelium 365 uplifted identity, endpoint and email controls across corporate, site and contractor users, aligning the environment to Essential Eight Maturity Level Two without disrupting operations on or off site.
The challenge
The firm's user base spans corporate roles in Perth, geologists and engineers on rotation, and short-term contractors working at remote sites with intermittent Starlink and 4G connectivity. Identity was fragmented across Microsoft 365, legacy on-premises Active Directory, and a handful of operational technology accounts that had never been reviewed.
A joint-venture partner had recently issued a security questionnaire referencing Essential Eight, and the firm's cyber insurer was tightening renewal requirements around MFA, privileged access, application control and patching. Several phishing incidents — including a credential-harvest targeting the CFO during a capital raise — had also raised concern at board level.
The approach
Mycelium 365 ran a focused assessment against Essential Eight, mapping current maturity, the gaps that mattered most for insurance and JV partner evidence, and the practical sequence to close them without disrupting field operations or drilling programs.
Identity was consolidated into Microsoft Entra ID with phishing-resistant MFA across all corporate, FIFO and contractor accounts. Privileged access was moved to just-in-time elevation with approval workflows, and standing global admin rights were removed. Conditional access enforced device compliance and location-aware controls suitable for remote and overseas travel.
Endpoints across HQ, site offices and FIFO laptops were brought under Microsoft Intune with Defender for Endpoint, a hardened Windows baseline, application control via Microsoft's managed installer model, and a patching cadence designed to tolerate intermittent satellite connectivity. Microsoft Defender for Office 365 was tuned for executive impersonation and supplier-payment fraud, with extra protections on finance and capital-raise mailboxes.
All changes were documented as evidence packs — policy exports, configuration screenshots and rollout records — so the firm could respond directly to JV partner questionnaires and insurer renewal questions without re-doing the work.
The outcome
The firm achieved practical alignment with Essential Eight Maturity Level Two across MFA, restrict admin privileges, application control, patch applications and patch operating systems, with documented evidence accepted by both the JV partner and the cyber insurer at renewal.
Standing global admin accounts were eliminated, and privileged actions now run through just-in-time elevation with full audit trail — a control the board specifically called out as a material risk reduction.
Phishing reports to the security inbox dropped sharply once Defender's impersonation protections were tuned, and the finance team reports no successful invoice-redirection or executive-impersonation incidents since go-live. FIFO and remote crews receive the same protections as HQ users, with no measurable impact on field productivity.
Technologies used
- Microsoft Entra ID (phishing-resistant MFA, conditional access)
- Entra Privileged Identity Management (just-in-time admin)
- Microsoft Intune (Windows baseline, application control)
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Essential Eight Maturity Level Two alignment and evidence pack
Need a similar outcome?
Book a Discovery Call with Mycelium 365 to discuss your environment, security priorities, and the practical next step.
