In this blog post Essential Eight and Microsoft 365 How Your Security Tools Fit we will explain why owning the right Microsoft licences does not automatically make your business secure or Essential Eight aligned. Many organisations have multi-factor authentication, antivirus and device policies, yet cannot show whether those controls cover every user, device and business system.
At a high level, the Essential Eight is the Australian government’s cybersecurity framework for reducing common attacks such as stolen accounts, malicious software and ransomware. Microsoft Intune, Defender and Entra ID can support much of that work, but each product has a different role and none of them delivers compliance on its own.
Essential Eight is a business risk program, not a product
The Essential Eight covers application control, patching applications, configuring Microsoft Office macros, hardening user applications, restricting administrative access, patching operating systems, multi-factor authentication and regular backups.
These controls are designed to work together. The Australian Signals Directorate recommends selecting a target maturity level based on risk and reaching the same level across all eight areas before progressing further. A strong result in multi-factor authentication cannot compensate for unsupported software or poor backup recovery.
This is where many Microsoft 365 projects go wrong. Technology is deployed one product at a time rather than as a coordinated security system with owners, measurable requirements and evidence.
Where Microsoft Intune fits
Microsoft Intune, which manages and secures company computers, phones and tablets, is the main policy and enforcement layer for endpoint devices. It lets your IT team define what a secure device should look like and apply that standard consistently.
Intune can support several Essential Eight areas:
- Operating system patching by controlling how quickly Windows security updates are tested and installed.
- Application control by helping restrict which programs, scripts and installers are allowed to run.
- Microsoft Office macro controls by blocking risky macros while allowing approved business use.
- User application hardening by applying safer settings to browsers, Office applications and Windows features.
- Restricting administrative privileges by reducing unnecessary local administrator access.
Intune can also mark devices as compliant or non-compliant. For example, a laptop might be considered unhealthy if it is missing updates, has security protection disabled or uses an outdated operating system.
That status becomes more valuable when it is connected to access decisions. Our guide to enforcing device compliance with Microsoft Intune explains how to define practical requirements without unexpectedly locking employees out.
Intune does not automatically patch every third-party application, protect every server or prove that policies are effective. Those gaps still need to be identified, assigned and monitored.
Where Microsoft Defender fits
Microsoft Defender is a family of security tools rather than one product. Defender for Endpoint protects computers and servers, while Defender for Office 365 focuses on threats arriving through email, links and collaboration tools.
For Essential Eight, Defender helps answer an important question: what is actually happening on your devices?
It can identify vulnerable software, detect suspicious behaviour and help security teams respond when an attack bypasses preventive controls. Its attack surface reduction features can also limit risky behaviour, such as an Office document attempting to launch another program.
This matters because a policy existing in an administration portal is not the same as that policy working. Defender provides the visibility needed to find devices that are drifting away from the standard or showing signs of compromise.
There is an important distinction, however. Defender may identify an urgent application vulnerability, but another tool or process may still be required to deploy the update. Detection without ownership can leave the risk unresolved.
Where Microsoft Entra ID fits
Microsoft Entra ID, formerly Azure Active Directory, manages user identities and decides who can access Microsoft 365 and other connected applications. It is central to the Essential Eight requirements for multi-factor authentication and restricting powerful administrator accounts.
Multi-factor authentication asks users for more than a password, such as a security key, device confirmation or biometric check. Entra ID can enforce this through Conditional Access, which applies different access rules based on the user, device, application, location and level of risk.
For higher Essential Eight maturity levels, organisations may need phishing-resistant authentication. This uses methods designed to prevent employees from accidentally approving a fake login page, such as security keys or Windows Hello for Business.
Entra ID also helps separate normal employee accounts from privileged administrator accounts. That reduces the damage possible if an administrator’s everyday email account is compromised.
Start with the practical checks in our guide to Microsoft Entra ID security settings every business should review. The goal is not simply to switch on more controls, but to close the access paths attackers are most likely to use.
The real value comes from joining the tools together
Consider an employee signing in from a laptop with missing updates and disabled endpoint protection. Intune identifies that the device does not meet company requirements, Defender supplies information about its security health, and Entra ID blocks or limits access through Conditional Access.
Instead of relying on the employee to notice the problem, the environment responds automatically. That reduces the period in which an unhealthy device can access sensitive files, email or cloud applications.
We explore this flow further in how Defender, Intune and Entra ID secure Microsoft 365 together. The business outcome is a more consistent security standard with fewer manual checks and fewer gaps between separate tools.
What Microsoft 365 does not solve by itself
A common mistake is assuming that a Microsoft 365 security project covers all eight controls. Regular backups still require decisions about what data is protected, how long it is retained, who can alter backup copies and how recovery will be tested.
You may also have business applications, cloud platforms, network equipment, servers or employee devices outside Intune and Defender. These systems remain part of the risk picture even when the Microsoft 365 tenant is well configured.
Licensing is another potential gap. Capabilities differ between Microsoft 365 plans, Defender products and Intune add-ons. Before buying more licences, map each requirement to the technology you already own and confirm whether it is configured, enforced and monitored.
A practical scenario for a 200-person business
Imagine a professional services company with around 200 employees. Multi-factor authentication is enabled for most users, Windows updates are largely automatic and antivirus is installed, so management believes the business is close to Essential Eight Maturity Level One.
A structured review finds unmanaged personal computers accessing company files, several employees with permanent administrator rights, inconsistent Office macro settings and no evidence that critical updates meet required timeframes. Backups exist, but recovery has not been tested recently.
The solution is not necessarily another security platform. The first priorities are to enrol company devices in Intune, connect device health to Entra Conditional Access, use Defender findings to prioritise remediation, remove unnecessary administrator access and test backup recovery.
This approach reduces immediate risk while avoiding duplicate tools and unnecessary licensing. It also gives leadership evidence showing what is covered, what remains outstanding and who owns each action.
How to turn Microsoft 365 into an Essential Eight program
- Choose a target maturity level. Base it on your threats, customer obligations, cyber insurance requirements and the sensitivity of your information.
- Define your scope. List users, computers, servers, applications, cloud services and data repositories that need protection.
- Map each requirement. Record whether Intune, Defender, Entra ID or another system provides the control.
- Check enforcement. Confirm that policies apply to the intended users and devices, including executives, contractors and administrators.
- Collect evidence. Keep reports showing update status, device compliance, authentication methods, administrator access and security alerts.
- Test the outcome. Verify that unmanaged devices are blocked, risky software cannot run and important data can be restored.
For identity and device access, our Conditional Access checklist for Microsoft 365 tenants provides a useful starting point.
Start with the gaps, not the licences
Intune, Defender and Entra ID can cover a significant part of an Essential Eight program when they are configured as one connected system. The result should be fewer successful account attacks, faster patching, safer devices and clearer evidence for customers, insurers and leadership.
CloudProInc brings more than 20 years of enterprise IT experience as a Microsoft Partner and Wiz Security Integrator, with practical expertise across Microsoft 365, Azure, Intune, Defender and Entra ID. If you are unsure whether your current Microsoft setup supports your Essential Eight target, we are happy to take a look and identify the most important gaps โ no strings attached.
Discover more from CPI Consulting
Subscribe to get the latest posts sent to your email.