RG Labs

Essential Eight Maturity Level 2 with Microsoft 365: a practical checklist

Most Australian mid-market organisations chasing Essential Eight Maturity Level 2 already own the majority of the tooling they need — it's sitting inside the Microsoft 365 E3 or E5 licence they pay for every month. The gap is rarely procurement. It's configuration, coverage and evidence.

This checklist walks the eight mitigation strategies in the order we'd tackle them for a Microsoft-anchored environment, flags what your licence tier actually covers, and is honest about where Microsoft alone won't get you to ML2.

A note on maturity levels. ML2 is the target the ACSC recommends for most organisations — it assumes adversaries willing to invest moderate effort in you specifically. ML1 stops commodity attacks; ML3 is for organisations facing well-resourced, targeted adversaries. Aim for ML2 across all eight before ML3 in any one.

1. Multi-factor authentication

Start here — it's the highest-leverage control and the fastest win in a Microsoft shop.

Licensing: Conditional Access needs Entra ID P1 (in E3). Risk-based policies need P2 (in E5).

2. Patch applications

Honest gap: Microsoft tooling sees Microsoft-managed endpoints well. Network appliances, servers off Intune, and third-party infrastructure usually need a dedicated scanner (Qualys, Tenable, Rapid7) to evidence ML2 properly.

3. Patch operating systems

4. Restrict administrative privileges

5. Application control

The control that most often stalls an ML2 program — and the one attackers most respect.

6. Restrict Microsoft Office macros

7. User application hardening

8. Regular backups

The part nobody tells you: evidence

ML2 isn't achieved when the policies are on — it's achieved when you can prove they're on, everywhere, continuously. Central logging of blocked executions, patch-latency reporting, access review artefacts, restore test records. Build the evidence trail as you deploy each control, not retrospectively before an audit. This is also where a SIEM earns its keep: Sentinel onboarding scoped to Essential Eight event sources gives you the ML2 logging requirements and detection value from the same work.

Want a graded read of where you actually stand?

Our Security Posture Assessment grades your Microsoft 365, Azure, AWS and Google Cloud configuration against the Essential Eight (plus ISO 27001, PCI-DSS, SOC 2 and CIS) from real configuration — not questionnaires — with a prioritised remediation roadmap.

Run your free check →