Essential Eight ML3 Uplift Planner
TL;DR: This skill reviews your current Essential Eight posture across all eight mitigation strategies and produces a prioritised, evidence-based plan to lift each control from Maturity Level 2 to Maturity Level 3.
What is the Essential Eight Maturity Model uplift?
The Essential Eight uplift moves each of the eight ACSC mitigation strategies from Maturity Level 2 to Maturity Level 3, using Microsoft Entra, Microsoft Intune and Microsoft Defender Vulnerability Management as evidence sources. The skill compares your tenant with the ML3 requirements Microsoft Learn maps to the ISM and lists the gaps.
When should you run this skill?
- “Show me where we sit against Essential Eight Maturity Level 3 today.”
- “What is blocking us from moving from ML2 to ML3?”
- “Build a prioritised Essential Eight uplift roadmap for the board.”
- “Which of the eight controls are furthest from Maturity Level 3?”
- “We have an IRAP assessment coming up; gap-assess our Essential Eight posture.”
- “Map our current MFA, patching, and application control settings to the ACSC maturity model.”
- “Give me a read-only Essential Eight scorecard before our annual review.”
How this skill works, step by step
- Confirm the target maturity level (Level 3) and the assessment scope across the eight controls: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multifactor authentication, and regular backups.
- Inspect Microsoft Entra for the authentication methods in use (Learn states that methods using cryptographic, session-bound authenticators satisfy the phishing-resistance requirement at ML2 and ML3) and for privileged role assignments managed through Microsoft Entra Privileged Identity Management.
- Review your configuration for application control, Microsoft Office macro settings and user application hardening against the requirements on the matching Microsoft Learn Essential Eight pages (these three pages are not cited here, so confirm them there).
- Query Microsoft Defender Vulnerability Management for vulnerabilities and missing patches, comparing your patch timeframes with the ML3 patching timeframes (for example, ISM-1692 requires patches for office productivity suites, web browsers and their extensions, email clients, PDF software and security products within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist).
- Review backup configuration to confirm restoration testing (ISM-1515, which Learn maps at Levels 1, 2 and 3) and, per the ACSC maturity model, that at Maturity Level Three accounts other than break glass accounts are prevented from modifying or deleting backups.
- Compare each observed setting against the documented Maturity Level 3 requirement and record a per-control status of Met, Partial, or Not Met.
- Derive a risk score per control: weight each unmet Level 3 requirement by adversary impact and exposure, then roll the weighted gaps into a 0-100 control score and an overall tenant score.
- Rank remediation items by risk score and implementation effort so the highest-impact, lowest-effort uplift actions surface first.
- Produce the prioritised uplift plan with control mappings, evidence references, and recommended Microsoft remediation actions.
Output format
The skill returns a per-control scorecard followed by a prioritised remediation summary. The rows below are an illustrative example, not real results, and the risk scores are this skill’s own weighting rather than a Microsoft or ACSC measure. Each row maps an Essential Eight control to its current status, the Level 3 gap, and a risk-weighted priority.
| Essential Eight control | Current level | ML3 status | Key gap | Risk score | Priority |
|---|---|---|---|---|---|
| Multifactor authentication | ML2 | Partial | Phishing-resistant MFA not enforced for all privileged access | 82 | High |
| Patch applications | ML2 | Not Met | Patches for office suites, browsers and similar software exceed 48 hours where vulnerabilities are critical or working exploits exist (ISM-1692) | 76 | High |
| Restrict administrative privileges | ML2 | Partial | Privileged access not limited to what duties require (ISM-1508); Learn maps this to just-in-time access through Microsoft Entra Privileged Identity Management | 64 | Medium |
| Regular backups | ML3 | Met | Restoration testing evidenced and backup modification limited to break glass accounts | 12 | Low |
Summary of the assessment:
- Each gap links to the specific Maturity Level 3 requirement and the Microsoft control that satisfies it.
- Remediation items are ordered by risk score then effort, giving a ready-to-action uplift roadmap.
- Controls already at Level 3 are listed with the evidence that confirms the rating.
Licensing and permissions
Microsoft Learn documents only some of these requirements, so confirm the rest in your own tenant.
| Capability used | Requirement documented on Microsoft Learn |
|---|---|
| Vulnerability and patch posture telemetry | Microsoft Defender Vulnerability Management standalone, or Microsoft Defender for Endpoint Plan 2 or E5 for a subset of capabilities |
| Portal access to Defender Vulnerability Management | At minimum, the Security Reader role |
| Continuous Essential Eight assessment | Microsoft Purview Compliance Manager Essential Eight premium templates at all three levels |
This page does not state licence tiers for Conditional Access or Privileged Identity Management, or Microsoft Graph permission scopes, so check current Microsoft Learn licensing pages and grant only read-only access before running the skill.
Scope and safety
This skill is read-only by default. It inspects configuration, policy, and posture telemetry to assess maturity and never changes tenant state.
This skill does NOT:
- Modify Conditional Access, Intune, patching, or backup configuration.
- Create, elevate, or remove privileged role assignments.
- Deploy patches, application control rules, or remediation actions on its behalf.
- Export, move, or alter any backup data or user content.
Related skills
- Essential Eight Maturity Self-Assessment: run before this to score each of the eight strategies.
- MFA and Strong Authentication Coverage Audit: run alongside this for the multifactor authentication gaps.
- Intune Device Compliance and Baseline Gap: run alongside this for device hardening and encryption gaps.
- E8 Evidence Packager: run after this to package evidence for an ML2 assessment.
- Australian Compliance for Microsoft 365 Copilot and AI: pillar page on Australian compliance evidence, including the Essential Eight.
Sources
Reviewed 2026-09-30 against the sources below.
Not verified: ML3 requirements for application control, Microsoft Office macro settings, user application hardening and patch operating systems, which this page does not state. The Learn ISM mappings (ISM controls as of March 2025) were checked against the Learn pages; the ACSC maturity model was checked only through search-result excerpts, so confirm exact wording on the ACSC page before relying on it.
- Essential Eight maturity model (cyber.gov.au) : the ACSC model; Maturity Level Three 48-hour patching, phishing-resistant MFA and backup protections.
- Essential Eight maturity model changes (cyber.gov.au) : states multi-factor authentication for users of systems is phishing-resistant at Maturity Level Three.
- Essential Eight maturity model and ISM mapping (cyber.gov.au) : mapping of the model to ISM controls.
- ACSC Essential Eight (Microsoft Learn) — the eight pillars, Compliance Manager premium templates at all three levels.
- Essential Eight patch applications (Microsoft Learn) — ISM-1692 (48 hours, ML3), Defender Vulnerability Management licensing and Security Reader role.
- Essential Eight restrict administrative privileges (Microsoft Learn) — ISM-1508 (ML3) and just-in-time access through Microsoft Entra Privileged Identity Management.
- Essential Eight multifactor authentication (Microsoft Learn) — phishing-resistant authenticators at ML2 and ML3.
- Essential Eight regular backups (Microsoft Learn) — ISM-1515 restoration testing and break-glass-only modification of backups.
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30 · Published 2026-06-04