Skip to Content
PurviewEssential Eight ML3 Uplift Planner

Essential Eight ML3 Uplift Planner

TL;DR: This skill reviews your current Essential Eight posture across all eight mitigation strategies and produces a prioritised, evidence-based plan to lift each control from Maturity Level 2 to Maturity Level 3.

What is the Essential Eight Maturity Model uplift?

The Essential Eight uplift moves each of the eight ACSC mitigation strategies from Maturity Level 2 to Maturity Level 3, using Microsoft Entra, Microsoft Intune and Microsoft Defender Vulnerability Management as evidence sources. The skill compares your tenant with the ML3 requirements Microsoft Learn maps to the ISM and lists the gaps.

When should you run this skill?

  • “Show me where we sit against Essential Eight Maturity Level 3 today.”
  • “What is blocking us from moving from ML2 to ML3?”
  • “Build a prioritised Essential Eight uplift roadmap for the board.”
  • “Which of the eight controls are furthest from Maturity Level 3?”
  • “We have an IRAP assessment coming up; gap-assess our Essential Eight posture.”
  • “Map our current MFA, patching, and application control settings to the ACSC maturity model.”
  • “Give me a read-only Essential Eight scorecard before our annual review.”

How this skill works, step by step

  1. Confirm the target maturity level (Level 3) and the assessment scope across the eight controls: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multifactor authentication, and regular backups.
  2. Inspect Microsoft Entra for the authentication methods in use (Learn states that methods using cryptographic, session-bound authenticators satisfy the phishing-resistance requirement at ML2 and ML3) and for privileged role assignments managed through Microsoft Entra Privileged Identity Management.
  3. Review your configuration for application control, Microsoft Office macro settings and user application hardening against the requirements on the matching Microsoft Learn Essential Eight pages (these three pages are not cited here, so confirm them there).
  4. Query Microsoft Defender Vulnerability Management for vulnerabilities and missing patches, comparing your patch timeframes with the ML3 patching timeframes (for example, ISM-1692 requires patches for office productivity suites, web browsers and their extensions, email clients, PDF software and security products within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist).
  5. Review backup configuration to confirm restoration testing (ISM-1515, which Learn maps at Levels 1, 2 and 3) and, per the ACSC maturity model, that at Maturity Level Three accounts other than break glass accounts are prevented from modifying or deleting backups.
  6. Compare each observed setting against the documented Maturity Level 3 requirement and record a per-control status of Met, Partial, or Not Met.
  7. Derive a risk score per control: weight each unmet Level 3 requirement by adversary impact and exposure, then roll the weighted gaps into a 0-100 control score and an overall tenant score.
  8. Rank remediation items by risk score and implementation effort so the highest-impact, lowest-effort uplift actions surface first.
  9. Produce the prioritised uplift plan with control mappings, evidence references, and recommended Microsoft remediation actions.

Output format

The skill returns a per-control scorecard followed by a prioritised remediation summary. The rows below are an illustrative example, not real results, and the risk scores are this skill’s own weighting rather than a Microsoft or ACSC measure. Each row maps an Essential Eight control to its current status, the Level 3 gap, and a risk-weighted priority.

Essential Eight controlCurrent levelML3 statusKey gapRisk scorePriority
Multifactor authenticationML2PartialPhishing-resistant MFA not enforced for all privileged access82High
Patch applicationsML2Not MetPatches for office suites, browsers and similar software exceed 48 hours where vulnerabilities are critical or working exploits exist (ISM-1692)76High
Restrict administrative privilegesML2PartialPrivileged access not limited to what duties require (ISM-1508); Learn maps this to just-in-time access through Microsoft Entra Privileged Identity Management64Medium
Regular backupsML3MetRestoration testing evidenced and backup modification limited to break glass accounts12Low

Summary of the assessment:

  • Each gap links to the specific Maturity Level 3 requirement and the Microsoft control that satisfies it.
  • Remediation items are ordered by risk score then effort, giving a ready-to-action uplift roadmap.
  • Controls already at Level 3 are listed with the evidence that confirms the rating.

Licensing and permissions

Microsoft Learn documents only some of these requirements, so confirm the rest in your own tenant.

Capability usedRequirement documented on Microsoft Learn
Vulnerability and patch posture telemetryMicrosoft Defender Vulnerability Management standalone, or Microsoft Defender for Endpoint Plan 2 or E5 for a subset of capabilities
Portal access to Defender Vulnerability ManagementAt minimum, the Security Reader role
Continuous Essential Eight assessmentMicrosoft Purview Compliance Manager Essential Eight premium templates at all three levels

This page does not state licence tiers for Conditional Access or Privileged Identity Management, or Microsoft Graph permission scopes, so check current Microsoft Learn licensing pages and grant only read-only access before running the skill.

Scope and safety

This skill is read-only by default. It inspects configuration, policy, and posture telemetry to assess maturity and never changes tenant state.

This skill does NOT:

  • Modify Conditional Access, Intune, patching, or backup configuration.
  • Create, elevate, or remove privileged role assignments.
  • Deploy patches, application control rules, or remediation actions on its behalf.
  • Export, move, or alter any backup data or user content.

Sources

Reviewed 2026-09-30 against the sources below.

Not verified: ML3 requirements for application control, Microsoft Office macro settings, user application hardening and patch operating systems, which this page does not state. The Learn ISM mappings (ISM controls as of March 2025) were checked against the Learn pages; the ACSC maturity model was checked only through search-result excerpts, so confirm exact wording on the ACSC page before relying on it.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-09-30 · Published 2026-06-04

Last updated on