---
name: E8 Evidence Packager
description: Compiles SharePoint permission reports, sharing summaries and Conditional Access policies into a versioned, indexed evidence folder to support an Essential Eight assessment.
lastReviewed: 2026-09-30
---

# E8 Evidence Packager

> **TL;DR:** This read-only skill collects SharePoint permission, sharing and Conditional Access records into a versioned, indexed evidence folder. The index notes which Essential Eight strategy each artefact may support. Assessors, not this skill, decide whether a control is met.

## How does the E8 Evidence Packager skill collect data-repository control evidence?

The E8 Evidence Packager is a read-only skill that gathers SharePoint site owner and admin lists, external sharing summaries and Microsoft Entra Conditional Access policies for each site in scope, then files them in a versioned, indexed evidence folder named for the assessment cycle, with an index noting the Essential Eight strategy each artefact may support.

## When should you run the E8 Evidence Packager?

Run the E8 Evidence Packager before an Essential Eight assessment walk-through or internal self-assessment, when you need each in-scope SharePoint site's permissions, sharing and Conditional Access evidence collected once, consistently and indexed, instead of assembled by hand from several admin portals.

Example prompts:

- "Package E8 evidence for this site"
- "Prepare ML2 evidence folder"
- "Collect audit artefacts for SharePoint"

## Evidence collected (per site)

The mapping below is this skill's own design. It lists evidence the skill can collect that may support a strategy. It is not a statement that the Essential Eight requires these artefacts, and an assessor may want different evidence.

| Artefact | Essential Eight strategy it may support |
| --- | --- |
| Site owner / admin list with last-reviewed dates | Restrict administrative privileges |
| Last backup / retention policy snapshot | Regular backups |
| Conditional Access policies applicable to the site | Multi-factor authentication |
| External sharing summary (link types, recipients) | No strategy mapped; supporting governance context only |
| Connected app inventory and last-updated dates | No strategy mapped; supporting context only, and not evidence of patching |

## What does Essential Eight Maturity Level Two mean?

The Essential Eight is a set of eight mitigation strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. Maturity Level Two targets malicious actors with a modest step-up in capability. ASD says it may suit large enterprises and is the baseline for non-corporate Commonwealth entities. The Essential Eight is assessed as a package, so evidence for three strategies here does not cover the other five. For administrative privileges, the maturity model includes requirements that privileged access to data repositories is validated when first requested and disabled after 12 months unless revalidated.

## How this skill works, step by step

1. Confirm the assessment cycle name (e.g. "2026-Q2 self-assessment")
2. Create the folder `Evidence/<cycle>/<site-name>/` in the destination library
3. For each artefact above, generate the artefact as a Markdown or CSV file with a timestamp header
4. Generate a top-level `INDEX.md` listing every artefact with file path, generation timestamp, and the strategy it may support (or "none mapped")
5. Produce a summary table for the consultant or assessor

## Output format

- Folder tree on disk (printed at end of run)
- `INDEX.md` lists each artefact with the strategy it may support, using the table above

## Scope and safety

This skill does NOT:

- Make compliance decisions (assessor / consultant judgment required)
- Modify production permissions or sharing settings
- Generate evidence for non-SharePoint workloads

## Licensing and permissions

### Licences

| Capability used | Licence |
| --- | --- |
| Microsoft Entra Conditional Access policy review | Microsoft Entra ID P1, or Microsoft 365 Business Premium |

Microsoft does not document a separate minimum licence for SharePoint site owner and sharing reports on the pages cited below, so none is stated here.

### Least-privilege roles

- Global Reader for site owner, admin and external sharing reads (Global Reader has read access to SharePoint Online PowerShell cmdlets and read APIs, and cannot take management actions)
- Security Reader, the minimum role Microsoft documents for viewing Conditional Access in the Microsoft Entra admin centre

### Microsoft Graph permissions (read-only)

- `Sites.Read.All` for site collection reads
- `Policy.Read.All` reads your organisation's policies (Microsoft Learn does not say here that this covers Conditional Access specifically, so confirm in your tenant)
- `Application.Read.All` reads applications and service principals for the connected app inventory
- `AuditLog.Read.All` for audit log reads

Microsoft Learn lists admin consent as required for the application form of `Policy.Read.All` and `Application.Read.All`. Check the permissions reference for the other two before granting. If you prefer not to use Microsoft Graph, the same reads can be made in the SharePoint admin centre, the Microsoft Entra admin centre and SharePoint Online PowerShell with read-only roles.

## Related skills

- [Essential Eight Maturity Self-Assessment](/purview/essential-eight-maturity-self-assessment): run before this to score the strategies and collect evidence pointers
- [IRAP Evidence Trail](/purview/irap-evidence-trail): run alongside this to organise governance documents by ISM family
- [ISM Control Pack](/purview/ism-control-pack): run alongside this to map tenant configuration to ISM controls
- [Site Permissions Baseline](/sharepoint/site-permissions-baseline): run before this to snapshot SharePoint site permissions
- [Australian Compliance for Microsoft 365 Copilot and AI](/purview/australian-copilot-compliance): start here for how Australian frameworks apply to Microsoft 365 Copilot

## Sources

Reviewed 2026-09-30 against the sources below. The artefact-to-strategy mapping is this skill's own design and is labelled as such.

- [Australian Signals Directorate, Essential Eight maturity model](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model)
- [Australian Signals Directorate, Essential Eight explained](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-explained)
- [Australian Signals Directorate, Essential Eight assessment process guide](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-assessment-process-guide)
- [Microsoft Learn, What is Conditional Access?](https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview)
- [Microsoft Learn, Overview of external sharing in SharePoint and OneDrive](https://learn.microsoft.com/en-us/sharepoint/external-sharing-overview)
- [Microsoft Learn, Microsoft Graph permissions reference](https://learn.microsoft.com/en-us/graph/permissions-reference)
- [Microsoft Learn, Microsoft Entra built-in roles](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference)
