Australian small businesses are increasingly targeted by cyber threats, yet most controls needed to reduce risk are practical, proven and achievable within a quarter. The ACSC Essential Eight is the national baseline. This guide maps each control to Microsoft 365, Entra ID, Intune, Defender and Azure—so you know exactly what to do, who should do it, and the order to roll it out.
At AZ Cloud Solutions, we run your Microsoft cloud so you can run your business. Our mission is simple: managed Microsoft 365, Azure and cybersecurity for Australian organisations—monitored around the clock, secured by design, and backed by a local team on a fixed monthly cost. Use this guide to move decisively toward Essential Eight maturity, then lean on us to keep it that way.
– It’s a prioritised set of eight mitigation strategies that materially lower the likelihood and impact of cyber incidents.
– Maturity ranges from Level One (basic) to Level Three (strong). Most SMEs should target Level Two as a practical, high-value baseline.
– Progress is measurable. You can track configurations, patching cadence and recovery tests against known outcomes.
Below are practical steps your team can start this month. Adjust for your licensing and risk profile.
Goal: Only trusted applications run.
– Choose your control:
– Intune + Microsoft Defender Application Control (WDAC) for modern, policy-based allow/deny lists.
– AppLocker (via Intune or Group Policy) for legacy/line-of-business needs.
– Start in audit mode to see what would be blocked.
– Create allow lists for signed Microsoft/Adobe binaries and your approved business apps.
– Block unsigned and script-based executables from user-writable locations.
– Phase rollout: pilot group > IT > all users. Monitor Defender alerts and Intune compliance before moving from audit to enforce.
Goal: Keep third‑party and Microsoft apps current.
– Standardise on Microsoft Edge (Enterprise) and Office current channels consistent with your change tolerance.
– Use Intune to:
– Deploy app updates via Microsoft Store for Business integration and Win32 packages.
– Leverage Winget for supported apps, with required assignments and deadlines.
– Establish a cadence:
– Critical security updates: pilot within 48 hours, broad deployment within 7–14 days after validation.
– Routine updates: monthly, aligned to Patch Tuesday validation windows.
– Measure compliance and missed SLAs via Intune reports; remediate stragglers with required installs.
Goal: Stop malicious macros while allowing legitimate, signed automation.
– In Intune Administrative Templates:
– Block macros from the internet.
– Allow only digitally signed macros for approved use cases.
– Enable Microsoft Defender Attack Surface Reduction (ASR) rules:
– Block Office apps from creating child processes.
– Block Office from injecting code into other processes.
– Block Win32 API calls from Office macros.
– Educate teams on using trusted locations and code signing for legitimate workflows.
Goal: Reduce the attack surface in browsers, document readers and email.
– Apply the Microsoft Security Baseline for Edge; turn on SmartScreen and network protection.
– Disable legacy plug-ins and restrict risky content types.
– Block executable content from email and webmail within Microsoft 365 Defender policies.
– Enable Controlled Folder Access in Defender to resist ransomware modifying protected directories.
Goal: Admin rights are rare, separate and time‑bound.
– Separate accounts: create distinct Entra ID admin accounts; no mailbox, no everyday use.
– Role-based access control: assign least-privileged roles in Entra ID; avoid global admin by default.
– Just‑in‑time access: if licensed, use Entra ID Privileged Identity Management (PIM) for approval/expiry.
– Remove local admin: manage via Intune; use Windows LAPS for unique, rotating local admin passwords.
– Lock down remote access with Conditional Access, compliant device requirements and location controls.
– Use hardened, dedicated “privileged access workstations” for sensitive tasks.
Goal: OS patches applied quickly and consistently.

– Configure Windows Update for Business (WUfB) in Intune:
– Create test, pilot and production update rings.
– Use Feature Update policies to pin or advance major versions when ready.
– Set deadlines and grace periods to enforce installs and restarts.
– Consider Windows Autopatch (if eligible) to automate ring management and deployment.
– Track compliance in Intune; remediate non-compliant devices with targeted policies.
Goal: MFA for all users, with phishing‑resistant options where possible.
– Enforce MFA with Entra ID Conditional Access for all users and admins.
– Prefer strong methods:
– Microsoft Authenticator with number matching.
– FIDO2 security keys or Windows Hello for Business for phishing resistance.
– Protect service accounts via workload identities and Conditional Access app controls.
– Maintain at least two emergency “break glass” accounts, excluded from CA, monitored and stored securely.
Goal: Rapid, reliable recovery with immutable copies.
– Microsoft 365: adopt a dedicated backup solution for Exchange Online, SharePoint, OneDrive and Teams to meet retention and point‑in‑time restore needs. Choose AU data residency where required.
– Azure workloads: use Azure Backup and Recovery Services vaults with immutability (write‑once, read‑many) and multi‑region resilience as appropriate.
– Follow 3‑2‑1: three copies, two media, one offsite/immutable.
– Test restores quarterly; document Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
Centralised visibility is non‑negotiable for Maturity Level Two and beyond.
– Connect data sources: Microsoft 365 Defender, Entra ID sign‑ins, Azure Activity, Defender for Endpoint, and applicable SaaS connectors.
– Use built‑in analytic rules for brute force, impossible travel, suspicious OAuth apps and endpoint anomalies; tune to reduce noise.
– Automate response with Logic Apps: disable accounts, quarantine endpoints, block senders, or open tickets.
– Retention and cost: tier logs by value; archive long‑term data cost‑effectively.
– Report monthly on incidents, mean‑time‑to‑respond and control coverage.
– Business sponsor: approves policy trade‑offs (e.g., macro restrictions), budget, and timelines.
– Internal IT or MSP (such as AZ Cloud Solutions): designs policies, deploys controls, monitors, and reports.
– Data owners and managers: validate app allow lists, retention needs and privileged access roles.
– All staff: complete security awareness and MFA onboarding; report suspicious activity quickly.
– Days 0–30: Foundations
– Enforce MFA with Conditional Access; create break‑glass accounts.
– Deploy Intune baselines, Windows Update rings and Defender ASR core rules.
– Stand up backup for Microsoft 365; test a sample restore.
– Onboard to Defender for Endpoint and connect Microsoft Sentinel.
– Days 31–60: Hardening
– Pilot WDAC/AppLocker; build allow lists; move pilots to enforce.
– Tighten admin privileges, remove local admin, and implement LAPS.
– Expand ASR, Edge hardening and executable content blocks in email.
– Validate patch cadence and compliance reporting.
– Days 61–90: Operationalise
– Roll out application control to all users.
– Finalise Feature Update policy and OS version targets.
– Enable Sentinel automation playbooks and tune analytic rules.
– Run a backup recovery drill and an incident response tabletop.
– Document policies, exceptions and an ongoing maintenance schedule.
– MFA enforced for all users and admins with strong methods.
– Intune managing every endpoint; update rings and feature policies in place.
– Application control deployed and monitored; exceptions documented.
– Office macros restricted; ASR rules enabled and validated.
– Admin privileges separated, least‑privileged and time‑bound; LAPS active.
– Third‑party and Microsoft apps patched on a defined schedule with compliance reporting.
– Immutable backups configured for M365 and Azure; quarterly restores tested.
– Sentinel connected to core data sources with alerts, automation and monthly reporting.
Moving from good intentions to working controls takes focused design, careful rollouts and 24/7 vigilance. AZ Cloud Solutions is a Microsoft Partner with Essential Eight–aligned hardening and local AU support seven days a week—all delivered on a fixed monthly cost. We manage Microsoft 365, Azure, Entra ID, Intune, Defender, SharePoint, Teams and Sentinel end‑to‑end so your people can simply get on with work.
We operate proactively by default, not reactively by the hour. Our site reports 99.98% tenant uptime over the last 30 days, average 11‑minute first response on P1 incidents, thousands of endpoints under management, high patch compliance and verified backups—because steady operations and clear reporting matter as much as smart configurations.
The Essential Eight is achievable for Australian SMEs without slowing the business. With Microsoft 365 and Azure, you already own the platform; it’s about configuring it with intent, enforcing it consistently and monitoring it continuously. Use the steps above to begin this month—and if you’d like a partner who does this every day, we’re here to help.
Ready to see where you stand? Book a free, no‑obligation assessment at https://azcloudsolutions.com.au/ and get a clear, prioritised plan to reach Maturity Level Two and beyond.
#EssentialEight #Microsoft365 #Azure #CyberSecurity #Intune #MicrosoftDefender #SMB #Australia #AZCloudSolutions