Essential Eight Maturity Level 2 with Microsoft 365: a practical checklist
Most Australian mid-market organisations chasing Essential Eight Maturity Level 2 already own the majority of the tooling they need — it's sitting inside the Microsoft 365 E3 or E5 licence they pay for every month. The gap is rarely procurement. It's configuration, coverage and evidence.
This checklist walks the eight mitigation strategies in the order we'd tackle them for a Microsoft-anchored environment, flags what your licence tier actually covers, and is honest about where Microsoft alone won't get you to ML2.
A note on maturity levels. ML2 is the target the ACSC recommends for most organisations — it assumes adversaries willing to invest moderate effort in you specifically. ML1 stops commodity attacks; ML3 is for organisations facing well-resourced, targeted adversaries. Aim for ML2 across all eight before ML3 in any one.
1. Multi-factor authentication
Start here — it's the highest-leverage control and the fastest win in a Microsoft shop.
- Enforce phishing-resistant MFA for all users via Conditional Access — not per-user legacy MFA and not Security Defaults. ML2 requires MFA that resists phishing for privileged users: Windows Hello for Business, FIDO2 keys or passkeys.
- Block legacy authentication outright. One Conditional Access policy; verify with sign-in logs first.
- Cover third-party and internet-facing services too. ML2 assesses your web apps and remote access, not just M365. Entra ID as the IdP for SaaS gets these under the same policy engine.
Licensing: Conditional Access needs Entra ID P1 (in E3). Risk-based policies need P2 (in E5).
2. Patch applications
- Scan for missing patches — ML2 expects at least fortnightly scanning, and within 48 hours for internet-facing services. Defender Vulnerability Management (E5, or add-on) covers endpoint visibility.
- Patch internet-facing services within two weeks, exploited vulnerabilities within 48 hours of a working exploit existing.
- Remove unsupported applications. An inventory you can defend is the prerequisite — Intune + DVM gives you one.
Honest gap: Microsoft tooling sees Microsoft-managed endpoints well. Network appliances, servers off Intune, and third-party infrastructure usually need a dedicated scanner (Qualys, Tenable, Rapid7) to evidence ML2 properly.
3. Patch operating systems
- Windows Update for Business rings via Intune — deferrals tight enough to land patches inside the one-month ML2 window, 48 hours for exploited vulnerabilities.
- No unsupported OS versions. Windows 10 past end-of-support fails you here regardless of anything else.
4. Restrict administrative privileges
- Separate admin accounts — cloud-only, mail-free, no internet browsing. Break glass accounts documented and monitored.
- PIM for just-in-time elevation (Entra P2/E5) with approval and time-boxing on privileged roles.
- Privileged access workstations or hardened jump paths for ML2's requirement that privileged environments are separated.
- Annual (or better) revalidation of privileged access — Entra Access Reviews automates the evidence.
5. Application control
The control that most often stalls an ML2 program — and the one attackers most respect.
- ML2 requires application control on workstations and internet-facing servers, enforcing an allowlist across executables, libraries, scripts, installers, compiled HTML and control panel applets, with blocked execution events centrally logged.
- WDAC (App Control for Business) can do this with no extra licence spend — but plan for a genuine pilot-audit-enforce cycle and real policy operations effort.
- ThreatLocker is often the pragmatic choice for lean teams: faster time-to-enforce, better day-two operations. Either path works; abandoned-in-audit-mode works for neither.
6. Restrict Microsoft Office macros
- Block macros from the internet and allow only for users with a demonstrated business need — enforced by Intune/GPO policy users can't override.
- Antivirus scanning of macros and blocked Win32 API calls from macros for ML2.
- Most organisations can disable macros for 90%+ of users immediately. Do that first, then handle the exceptions properly.
7. User application hardening
- Internet Explorer 11 disabled or removed; Java from the internet blocked.
- Browser hardening via Intune Edge/Chrome baselines — and users can't change the settings.
- ML2 adds hardening for Office and PDF readers per vendor guidance (ASR rules do much of this), with blocked PowerShell script events logged centrally.
8. Regular backups
- M365 retention is not a backup strategy. ML2 expects backups of important data, software and settings, tested restoration, and retention aligned to business criticality.
- Privileged accounts must not be able to modify or delete backups — immutability and separation of the backup control plane from your production tenant identity matter here.
The part nobody tells you: evidence
ML2 isn't achieved when the policies are on — it's achieved when you can prove they're on, everywhere, continuously. Central logging of blocked executions, patch-latency reporting, access review artefacts, restore test records. Build the evidence trail as you deploy each control, not retrospectively before an audit. This is also where a SIEM earns its keep: Sentinel onboarding scoped to Essential Eight event sources gives you the ML2 logging requirements and detection value from the same work.
Want a graded read of where you actually stand?
Our Security Posture Assessment grades your Microsoft 365, Azure, AWS and Google Cloud configuration against the Essential Eight (plus ISO 27001, PCI-DSS, SOC 2 and CIS) from real configuration — not questionnaires — with a prioritised remediation roadmap.
Run your free check →