---
name: Essential Eight Maturity Self-Assessment
description: Self-assess your Microsoft 365 tenant against all eight ACSC Essential Eight strategies and produce a maturity scorecard with evidence pointers.
lastReviewed: 2026-09-30
---

# Essential Eight Maturity Self-Assessment

> **TL;DR:** This skill inspects your Microsoft 365 tenant read-only and scores each of the eight Essential Eight mitigation strategies against Maturity Levels 1 to 3, with evidence pointers for each finding.

## How does the Essential Eight map to Microsoft 365?

The Essential Eight is the Australian Cyber Security Centre (ACSC) baseline of eight mitigation strategies, and in a Microsoft 365 tenant most controls are evidenced through Microsoft Entra, Microsoft Intune, Microsoft Defender for Endpoint and Microsoft Defender Vulnerability Management, with Microsoft Purview Compliance Manager monitoring drift. Microsoft Learn publishes one guide per strategy that maps controls to Information Security Manual (ISM) identifiers. The ACSC maturity model has three target levels, based on mitigating increasing levels of tradecraft and targeting, plus Maturity Level 0, which captures instances where the Maturity Level 1 requirements are not met.

## When should you run this skill?

Run this skill when you need a read-only Essential Eight scorecard for a Microsoft 365 tenant, for example before a security audit, when reporting under the Protective Security Policy Framework, or when you need to find which of the eight strategies sit below your target maturity level.

- "Where do we sit against the Essential Eight right now?"
- "Give me an Essential Eight scorecard before our security audit."
- "Which Essential Eight strategies are below Maturity Level 2?"
- "We are a Commonwealth entity and need evidence for our PSPF reporting."
- "Show me the gaps in our patching and MFA posture against the ACSC baseline."
- "Produce a board-ready maturity summary across all eight strategies."
- "What evidence backs each Essential Eight rating in our tenant?"

## How this skill works, step by step

1. Confirm read-only access to Microsoft Entra, Microsoft Intune and the Microsoft Defender portal for the target tenant.
2. Inspect multifactor authentication coverage and whether the Microsoft Entra authentication methods in use are phishing-resistant, for the MFA strategy.
3. Read Microsoft Intune application control (AppLocker or Windows Defender Application Control), Attack Surface Reduction and Windows Update for Business update ring configuration, for application control, user application hardening and patch operating systems.
4. Query Microsoft Defender Vulnerability Management for missing patches across applications and operating systems, to score the two patching strategies.
5. Review Office hardening settings deployed through Intune, for the configure Microsoft Office macro settings strategy.
6. Inspect Microsoft Entra Privileged Identity Management role assignments and just-in-time configuration, for restrict administrative privileges.
7. Review backup configuration signals for the regular backups strategy.
8. Map each observed signal to the relevant ISM control and maturity level (1, 2 or 3).
9. Derive a per-strategy rating using this skill's own scoring method (not an ACSC procedure): assign the highest maturity level for which all required controls are evidenced, report Maturity Level 0 when a Maturity Level 1 requirement is not evidenced, and record an evidence pointer for every rating. For a formal assessment, use the ACSC Essential Eight assessment process guide.

## Output format

The skill returns one row per Essential Eight strategy with its assessed maturity level and an evidence pointer. The rows below are illustrative examples, not real findings.

| Strategy | Target ML | Assessed ML | Evidence pointer |
| --- | --- | --- | --- |
| Multifactor authentication | 2 | 2 | Sign-ins for all users require a phishing-resistant Microsoft Entra authentication method |
| Patch applications | 2 | 1 | Defender Vulnerability Management shows 14 apps with patches older than 2 weeks (ISM-1691) |
| Restrict administrative privileges | 3 | 2 | No Microsoft Entra PIM just-in-time activation configured for Global Administrator (ISM-1508) |

Summary bullets accompany the table:

- Overall posture expressed as the lowest assessed maturity level across all eight strategies (this skill's own summary convention; the ACSC advises planning to reach the same maturity level across all eight strategies).
- Count of strategies meeting, exceeding, or falling below the target maturity level.
- Highest-priority gaps ranked by maturity shortfall and mapped ISM control.

## Licensing and permissions

### Licences and add-ons

Microsoft Learn documents the following for the signals this skill reads. It does not publish a per-capability licence table for Microsoft Entra or Microsoft Intune in the cited pages, so confirm those against your own agreement.

| Capability used | Licence per Microsoft Learn |
| --- | --- |
| Vulnerability and patch signals | Microsoft Defender Vulnerability Management standalone, or Microsoft Defender for Endpoint Plan 2 (or E5) for a subset, with full capabilities as an add-on |
| Continuous compliance monitoring | Microsoft Purview Compliance Manager Essential Eight premium templates (Microsoft Learn names the templates but does not state a licence requirement) |

### Least-privilege roles

- Security Reader is the minimum role Microsoft Learn names for accessing Microsoft Defender Vulnerability Management in the Microsoft Defender portal.
- Other read-only roles and Microsoft Graph permissions depend on your tenant design. Microsoft Learn does not specify them for the Essential Eight, so grant only what your reviewers need.

## Scope and safety

This skill is read-only by default and makes no changes to tenant configuration, policies, or device state.

This skill does NOT:

- Modify, create, or remove any access policy, role assignment, or Intune configuration.
- Deploy patches, enforce application control, or change macro settings.
- Export user content, mailbox data, or personal information.
- Grant, elevate, or activate any privileged role.

## Frequently asked questions

### Is the Essential Eight mandatory in Australia?

Maturity Level 2 of the Essential Eight is mandatory for Australian non-corporate Commonwealth entities subject to the PGPA Act. The Protective Security Policy Framework states that entities must implement the Maturity Level 2 requirements of the Essential Eight Maturity Model to attain a 'Managing' maturity level for each mandatory strategy, and Microsoft Learn cites PSPF Section 14.2 for this requirement. The PSPF is amended by directions and policy advisories, so confirm the current requirement at protectivesecurity.gov.au before relying on it. Microsoft Learn also states that the ACSC recommends all Australian organisations implement the eight strategies as a baseline.

### How quickly must applications be patched?

Under ISM-1691, patches for office productivity suites, web browsers, email clients, PDF software and security products must be applied within two weeks of release at Maturity Levels 1 and 2. ISM-1693 allows one month for other applications at Levels 2 and 3, and ISM-1692 requires 48 hours for critical vulnerabilities in those products at Level 3.

### Does Essential Eight multifactor authentication need to be phishing-resistant?

Yes at Maturity Levels 2 and 3, with the ACSC exception of customers authenticating to online customer services. Microsoft Learn explains that Microsoft Entra authentication methods meeting those levels use cryptographic authenticators bound to the session, whereas manually entered one-time codes are not considered verifier impersonation-resistant under NIST guidance, so they can be phished by a man-in-the-middle attack.

### Which Microsoft tool keeps Essential Eight compliance from drifting?

Microsoft recommends Microsoft Purview Compliance Manager for continuous compliance. Its Essential Eight premium templates cover all three maturity levels and help with monitoring, continuous assessment and configuration drift, because an assessment using the Learn guides is only a point-in-time activity.

## Related skills

- [Microsoft Secure Score Improvement Plan](/purview/secure-score-improvement-plan): run before this to see open improvement actions mapped to the Essential Eight.
- [Defender ASR and Endpoint Config Assessment](/purview/defender-asr-config-assessment): run alongside this for detail on application hardening.
- [Essential Eight ML3 Uplift Planner](/purview/essential-eight-ml3-uplift): run after this to plan the uplift from Maturity Level 2 to Level 3.
- [E8 Evidence Packager](/purview/e8-evidence-packager): run after this to package evidence for an ML2 assessment.
- [Australian Compliance for Microsoft 365 Copilot and AI](/purview/australian-copilot-compliance): pillar page on Australian compliance evidence, including the Essential Eight.

## Sources

Reviewed 2026-09-30 against the sources below. The ACSC maturity level descriptions, Maturity Level 0 definition, the ISM-1691, ISM-1692 and ISM-1693 patch timeframes and the PSPF Maturity Level 2 requirement (as stated on the PSPF policy amendment page; later PSPF directions may change it) and the phishing-resistant MFA wording at Levels 2 and 3 were checked against cyber.gov.au and protectivesecurity.gov.au search results; the Microsoft mappings (ISM identifiers, licensing, Security Reader, Compliance Manager templates) were checked against the Microsoft Learn pages. The per-strategy scoring method and the lowest-level overall summary are this skill's own design. The individual ML1 to ML3 requirement text for each strategy was not re-verified beyond the patching controls and is delegated to the ACSC model.

- [ACSC Essential Eight Maturity Model](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model): the ACSC model, its three maturity levels and Maturity Level 0.
- [Essential Eight explained (cyber.gov.au)](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-explained): the eight strategies and planning for the same maturity level across all eight.
- [Essential Eight maturity model and ISM mapping (cyber.gov.au)](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model-and-ism-mapping): mapping of Essential Eight requirements to ISM controls.
- [Essential Eight assessment process guide (cyber.gov.au)](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-assessment-process-guide): the ACSC method for formal assessments.
- [Policy amendment: Information security (PSPF)](https://www.protectivesecurity.gov.au/news/policy-amendment-information-security): Maturity Level 2 requirement for non-corporate Commonwealth entities.
- [ACSC Essential Eight overview (Microsoft Learn)](https://learn.microsoft.com/en-us/compliance/anz/e8-overview): eight pillars, PSPF 14.2 requirement, Purview Compliance Manager premium templates.
- [Essential Eight multifactor authentication](https://learn.microsoft.com/en-us/compliance/anz/e8-mfa): phishing resistance at Maturity Levels 2 and 3.
- [Essential Eight patch applications](https://learn.microsoft.com/en-us/compliance/anz/e8-patch-app): ISM-1691, ISM-1692, ISM-1693, Defender Vulnerability Management licensing and Security Reader.
- [Essential Eight restrict administrative privileges](https://learn.microsoft.com/en-us/compliance/anz/e8-admin): ISM-1508 and Microsoft Entra PIM just-in-time access.
- [Essential Eight application control](https://learn.microsoft.com/en-us/compliance/anz/e8-app-control): ISM-1657, AppLocker and Windows Defender Application Control.
- [Essential Eight user application hardening](https://learn.microsoft.com/en-us/compliance/anz/e8-app-harden): ISM-1667 to ISM-1669 Attack Surface Reduction rules and Office hardening.
- [Essential Eight regular backups](https://learn.microsoft.com/en-us/compliance/anz/e8-backups): the regular backups strategy.
