Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Getting compliant

Most of Cyber Essentials is already in your tenant

If you run Microsoft 365, the five controls map onto settings you can change this afternoon. Here is which ones, and the two places licensing gets in the way.

Fast Cyber Essentials › On Microsoft 365

A large share of UK small and medium organisations run Microsoft 365, and for them Cyber Essentials is less a project than a configuration review. The controls map onto things already in the tenant. Knowing which saves a great deal of guessing.

What follows is the mapping. It is deliberately not a click-by-click guide, because Microsoft moves the menus and a guide written today is wrong by spring. It tells you what to look for.

Firewalls

For a cloud-first estate the boundary firewall requirement largely falls on the device rather than on an office perimeter. What you need is the host firewall enabled on every device, enforced centrally rather than left to the user.

In Intune this is an endpoint security firewall policy applied to all devices. The thing to check is not whether the policy exists but whether every device is actually receiving it, because devices that never enrolled properly sit outside policy and still look fine in a list.

Secure configuration

Three parts.

Device configuration. Screen lock enforced with a timeout, auto-run disabled, unnecessary software removed. Intune configuration profiles handle the first two. The third is a manual exercise nobody enjoys.

Password policy. The scheme wants one of: multi-factor authentication, or twelve characters minimum, or eight characters plus automated blocking of common passwords. If you have MFA everywhere you have satisfied it. Turn off forced periodic expiry, which the scheme discourages and which Microsoft also recommends against.

Default accounts. Removed or renamed with a strong password. The one people forget is the break-glass global administrator account created during tenant setup, which needs to be documented, strongly protected and excluded from conditional access deliberately rather than accidentally.

Security update management

Critical and high severity updates within fourteen days. Windows Update for Business through Intune does this, but two details decide whether you pass.

First, deferral periods. A quality update deferral of more than fourteen days puts you outside the requirement by configuration, regardless of what actually happens. Check the number rather than assuming.

Second, applications. Windows updates are the easy part. Browsers, PDF readers, Java, and line-of-business applications all need a patching route, and "users update them when prompted" is not one. This is where most estates are genuinely non-compliant.

Unsupported software is an automatic fail, and it has to be removed from scope, removed from the estate, or segregated so it cannot reach the internet and cannot be reached from it.

User access control

The control that fails most often, and the one Microsoft 365 helps with most.

MFA on every cloud service for every user. Security defaults cover this for smaller tenants. Conditional access gives finer control if you are licensed for it. Either is acceptable; having neither is not.

Administrative accounts used only for administration. Separate admin accounts, not your daily account with a role attached. Where you are licensed for it, privileged identity management makes this cleaner by granting the role only when needed.

No local administrator rights for day-to-day work. This is the one to audit rather than assume. Intune can enforce it and can grant temporary elevation where somebody genuinely needs it.

Leavers. A documented process, and accounts actually disabled. Orphaned accounts of former staff or a previous IT supplier are a common finding.

Malware protection

Microsoft Defender Antivirus, enabled, updating, and not silently disabled on a subset of machines. Verify centrally rather than trusting the policy. The failure mode is a handful of devices where somebody turned it off during troubleshooting and never turned it back on.

Where licensing gets in the way

Two requirements where the licence tier matters
RequirementThe issue
Conditional accessNeeds a higher tier than Business Basic or Standard. Security defaults satisfy the MFA requirement without it, but give you no granularity.
Intune device managementIncluded in Business Premium and the enterprise tiers, not in Basic or Standard. Without it, evidencing device configuration across a fleet becomes a manual exercise.

For organisations on Business Standard, moving to Business Premium is frequently the cheapest route to certification, because it turns per-device manual evidence into centrally enforced policy. Worth pricing that against the time cost of the alternative before assuming it is an expense.

What Microsoft 365 does not do for you

Scope definition. Unsupported software still running somewhere. Personal devices outside management. Anything not in the tenant at all: the standalone server, the network appliance, the machine in the workshop running the machine.

Those are the parts that need actual work, and they are usually where the weeks go.

The order to do it in

Configuration changes in a tenant have a sequence that avoids locking yourself out or generating a week of support calls. This is the order that works.

  1. Create and protect a break-glass account first. A cloud-only global administrator, with a long unique password stored offline, deliberately excluded from conditional access. Do this before you touch anything else, because every subsequent step increases the chance of locking yourself out.
  2. Inventory the cloud services. Before enforcing anything. Enterprise applications in your identity provider, software subscriptions in expense records, and a direct question to each department head.
  3. Enable multi-factor authentication, in stages. Administrators first, then a pilot group, then everyone. Enforcing tenant-wide on a Monday morning with no warning produces a bad week and a lasting reluctance to change anything.
  4. Enrol devices into management. Before applying restrictive policy, so you can see what you have.
  5. Apply configuration policy. Firewall, screen lock, malware protection settings. Pilot group first.
  6. Set patching policy and check the deferral numbers. Fourteen days for quality updates, and verify the setting rather than trusting the dashboard.
  7. Remove local administrator rights last. This is the change users notice. Do it with an elevation route already in place so people can still work.
  8. Then audit everything. Pull the reports and find the devices that never enrolled, never reported, or slipped through.

The step most people skip

Step eight. Applying policy feels like completing the task, and the dashboard turning green reinforces that. But dashboards report on devices that are checking in, and the devices that will cause your submission to be inaccurate are precisely the ones that are not.

Reconcile three lists before you answer anything: devices in your management tooling, devices in your identity provider, and devices in your asset records. The differences between those three are the real estate, and they are where a confident answer becomes an inaccurate one.

Do security defaults satisfy the MFA requirement?

Yes. Security defaults enforce MFA for all users and are an acceptable way to meet the requirement. Conditional access gives you finer control and needs a higher licence tier, but it is not required for certification.

Do we need Business Premium to certify?

No, but it is often the cheapest route. Without Intune you can still certify, you just have to evidence device configuration manually. At ten devices that is fine. At eighty it is usually more expensive in time than the licence upgrade costs.

What patch deferral setting is acceptable?

Whatever ensures critical and high severity updates are applied within fourteen days of release. A quality update deferral longer than that puts you outside the requirement by configuration, regardless of what happens in practice.

Is Microsoft Defender enough for malware protection?

Yes, provided it is enabled, updating and not disabled on any device in scope. Built-in protection on current Windows and macOS is acceptable. What fails is a subset of machines where it was turned off and never turned back on.

Want your tenant checked against the controls?

The gap analysis reviews your actual configuration against all five controls and tells you exactly what to change, in a form your IT provider can action.