E8 Evidence Packager
TL;DR: This read-only skill collects SharePoint permission, sharing and Conditional Access records into a versioned, indexed evidence folder. The index notes which Essential Eight strategy each artefact may support. Assessors, not this skill, decide whether a control is met.
How does the E8 Evidence Packager skill collect data-repository control evidence?
The E8 Evidence Packager is a read-only skill that gathers SharePoint site owner and admin lists, external sharing summaries and Microsoft Entra Conditional Access policies for each site in scope, then files them in a versioned, indexed evidence folder named for the assessment cycle, with an index noting the Essential Eight strategy each artefact may support.
When should you run the E8 Evidence Packager?
Run the E8 Evidence Packager before an Essential Eight assessment walk-through or internal self-assessment, when you need each in-scope SharePoint site’s permissions, sharing and Conditional Access evidence collected once, consistently and indexed, instead of assembled by hand from several admin portals.
Example prompts:
- “Package E8 evidence for this site”
- “Prepare ML2 evidence folder”
- “Collect audit artefacts for SharePoint”
Evidence collected (per site)
The mapping below is this skill’s own design. It lists evidence the skill can collect that may support a strategy. It is not a statement that the Essential Eight requires these artefacts, and an assessor may want different evidence.
| Artefact | Essential Eight strategy it may support |
|---|---|
| Site owner / admin list with last-reviewed dates | Restrict administrative privileges |
| Last backup / retention policy snapshot | Regular backups |
| Conditional Access policies applicable to the site | Multi-factor authentication |
| External sharing summary (link types, recipients) | No strategy mapped; supporting governance context only |
| Connected app inventory and last-updated dates | No strategy mapped; supporting context only, and not evidence of patching |
What does Essential Eight Maturity Level Two mean?
The Essential Eight is a set of eight mitigation strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. Maturity Level Two targets malicious actors with a modest step-up in capability. ASD says it may suit large enterprises and is the baseline for non-corporate Commonwealth entities. The Essential Eight is assessed as a package, so evidence for three strategies here does not cover the other five. For administrative privileges, the maturity model includes requirements that privileged access to data repositories is validated when first requested and disabled after 12 months unless revalidated.
How this skill works, step by step
- Confirm the assessment cycle name (e.g. “2026-Q2 self-assessment”)
- Create the folder
Evidence/<cycle>/<site-name>/in the destination library - For each artefact above, generate the artefact as a Markdown or CSV file with a timestamp header
- Generate a top-level
INDEX.mdlisting every artefact with file path, generation timestamp, and the strategy it may support (or “none mapped”) - Produce a summary table for the consultant or assessor
Output format
- Folder tree on disk (printed at end of run)
INDEX.mdlists each artefact with the strategy it may support, using the table above
Scope and safety
This skill does NOT:
- Make compliance decisions (assessor / consultant judgment required)
- Modify production permissions or sharing settings
- Generate evidence for non-SharePoint workloads
Licensing and permissions
Licences
| Capability used | Licence |
|---|---|
| Microsoft Entra Conditional Access policy review | Microsoft Entra ID P1, or Microsoft 365 Business Premium |
Microsoft does not document a separate minimum licence for SharePoint site owner and sharing reports on the pages cited below, so none is stated here.
Least-privilege roles
- Global Reader for site owner, admin and external sharing reads (Global Reader has read access to SharePoint Online PowerShell cmdlets and read APIs, and cannot take management actions)
- Security Reader, the minimum role Microsoft documents for viewing Conditional Access in the Microsoft Entra admin centre
Microsoft Graph permissions (read-only)
Sites.Read.Allfor site collection readsPolicy.Read.Allreads your organisation’s policies (Microsoft Learn does not say here that this covers Conditional Access specifically, so confirm in your tenant)Application.Read.Allreads applications and service principals for the connected app inventoryAuditLog.Read.Allfor audit log reads
Microsoft Learn lists admin consent as required for the application form of Policy.Read.All and Application.Read.All. Check the permissions reference for the other two before granting. If you prefer not to use Microsoft Graph, the same reads can be made in the SharePoint admin centre, the Microsoft Entra admin centre and SharePoint Online PowerShell with read-only roles.
Related skills
- Essential Eight Maturity Self-Assessment: run before this to score the strategies and collect evidence pointers
- IRAP Evidence Trail: run alongside this to organise governance documents by ISM family
- ISM Control Pack: run alongside this to map tenant configuration to ISM controls
- Site Permissions Baseline: run before this to snapshot SharePoint site permissions
- Australian Compliance for Microsoft 365 Copilot and AI: start here for how Australian frameworks apply to Microsoft 365 Copilot
Sources
Reviewed 2026-09-30 against the sources below. The artefact-to-strategy mapping is this skill’s own design and is labelled as such.
- Australian Signals Directorate, Essential Eight maturity model
- Australian Signals Directorate, Essential Eight explained
- Australian Signals Directorate, Essential Eight assessment process guide
- Microsoft Learn, What is Conditional Access?
- Microsoft Learn, Overview of external sharing in SharePoint and OneDrive
- Microsoft Learn, Microsoft Graph permissions reference
- Microsoft Learn, Microsoft Entra built-in roles
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30 · Published 2026-06-02