Cyber Essentials
Northwind Traders has 4 controls to fix before applying for Cyber Essentials.
Judged from Microsoft 365 data collected ; 19 controls need evidence Microsoft 365 can't show.
What changed
Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal, which comes round every 12 months.
Fix before you apply
6 controls-
Legacy authentication is allowed. No enabled policy blocks legacy authentication for all users.
Fix: Block legacy authentication. See the rows →
-
5 of 36 Windows computers past end of support. For example LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release. See the rows →
-
4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.
Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →
-
1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →
-
1 disabled account still licensed. For example robert.hughes@northwindtraders.example: Disabled, holding 1 licence.
Fix: Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes. See the rows →
-
1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.
Fix: Remove admin roles from guest accounts. See the rows →
Firewalls
Your evidenceEvery device and network in scope sits behind a firewall that blocks unauthenticated inbound connections by default, with changed passwords, reviewed rules and no administration from the internet.
A boundary firewall (or the router's firewall) protects each internet connection, and home workers are protected by the firewall on their device.
A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.
What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.
Write this answer for Northwind Traders
The built-in firewall is turned on for every laptop, desktop and server.
The built-in software firewall (Microsoft Defender Firewall on Windows, the macOS firewall on Macs) is turned on for all computers and servers [and enforced by Intune policy].
What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.
Write this answer for Northwind Traders
The default administrator password of every router and firewall was changed to a strong one.
The default administrator passwords on all firewalls and routers were changed when they were installed, to [unique passwords of at least 12 characters, kept in a password manager].
What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.
Write this answer for Northwind Traders
Inbound rules are reviewed and removed when no longer needed, at least yearly.
Firewall rules are reviewed [every 12 months] by [IT provider], and rules that are no longer needed are removed. The last review was on [date].
What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.
Write this answer for Northwind Traders
The firewall blocks inbound connections unless an approved, documented rule allows one (A4.8).
Firewalls block all inbound connections by default. [No inbound connections are allowed.] or [Each allowed inbound connection is documented, with its business need approved by (role).]
What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.
Write this answer for Northwind Traders
The firewall's administration interface can't be reached from the internet, or only with MFA or from an allow list of trusted addresses with a documented need (A4.10, A4.11).
The firewall's administration interface can't be reached from the internet. [Or: remote administration is limited to (trusted IP addresses) and protected by multi-factor authentication.]
What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.
Write this answer for Northwind Traders
Secure configuration
FailDevices and cloud services run only the software, services and accounts they need, with default passwords changed, automatic running of files off and devices that lock.
Software and services nobody uses are removed or turned off on every device.
New devices are set up from [a standard build or Windows Autopilot] without unnecessary software, and unused software and services are removed [during regular reviews by the IT provider].
What Microsoft 365 can't show: Microsoft 365 doesn't report what's installed on devices.
Write this answer for Northwind Traders
Services that aren't needed are turned off in cloud services too: for Microsoft 365, the legacy sign-in protocols that can't use MFA, and SMTP AUTH on mailboxes that don't send mail that way.
- Legacy authentication is allowed.
- No enabled policy blocks legacy authentication for all users
- SMTP AUTH is on for the organisation.
- SMTP AUTH is allowed
Fix: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target. See the rows →
Legacy authentication is allowed. SMTP AUTH is on for the organisation.
What Microsoft 365 can't show: Judged from Conditional Access and Exchange Online settings.
Devices and cloud services hold only the user accounts in use: no leftover licensed-but-disabled accounts and no forgotten guest invitations.
- No stale guest invitations.
- 1 disabled account still licensed.
- robert.hughes@northwindtraders.example: Disabled, holding 1 licence
Fix: Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes (free up to 50 GB) before removing the licence. See the rows →
No stale guest invitations. 1 disabled account still licensed.
What Microsoft 365 can't show: Judged from Microsoft Entra ID accounts and guest invitations. Add local accounts on devices and servers.
Default and built-in account passwords are changed at set-up.
Default and built-in accounts on devices are turned off or given new passwords at set-up. [Local administrator passwords are managed by Windows LAPS.]
What Microsoft 365 can't show: Microsoft 365 accounts have no default password; this is about devices and built-in accounts.
Write this answer for Northwind Traders
AutoRun and AutoPlay are off, and downloaded files don't run without the user's say-so.
AutoPlay and AutoRun are turned off on Windows computers [by Intune policy], and downloaded files can't run without the user's permission.
What Microsoft 365 can't show: Office Sentry doesn't read device configuration profiles from Intune, so answer from the Intune policy.
Write this answer for Northwind Traders
Every device locks after inactivity and unlocks with a password, PIN of at least six digits or biometric (A5.10), with brute-force protection.
Computers lock after [5 to 15] minutes of inactivity and need a password, PIN or Windows Hello to unlock. Phones and tablets need a PIN of at least 6 digits or biometrics [enforced by Intune].
What Microsoft 365 can't show: Office Sentry doesn't read device configuration profiles from Intune, so answer from the Intune policy.
Write this answer for Northwind Traders
Security update management
FailEvery operating system and application is supported by its vendor, licensed, set to update automatically where possible, and has high-risk and critical updates installed within 14 days.
All operating systems in scope receive regular security updates from their vendor; Windows 10 needs Extended Security Updates after October 2025.
- Computers managed by Intune
- 36
- Of which encrypted
- 32
- Windows computers out of support
- 5
- Reaching end of support within 90 days
- 20
- Not compliant
- 6
- 5 of 36 Windows computers past end of support.
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- and 20 more
Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. See the rows →
Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.
What Microsoft 365 can't show: Judged for Windows computers known to Intune or Entra ID. macOS, Linux, phones, servers not joined to Entra ID and router or firewall firmware aren't seen.
Change this answer
Browsers, anti-malware, email and office applications are supported versions (A6.2.1 to A6.2.4), nothing is unlicensed or unsupported (A6.3, A6.6), and any unsupported software is on a separate sub-set (A6.7).
All software in use is supported by its vendor and licensed: [browser and version], [anti-malware product and version], [email application and version] and [office applications and version]. Software that is no longer supported has been removed[, or runs on a separate sub-set outside the scope].
What Microsoft 365 can't show: Microsoft 365 doesn't report installed application versions. Intune's discovered apps would need a permission the app doesn't hold.
Write this answer for Northwind Traders
High-risk and critical security updates for operating systems, routers and firewalls are installed within 14 days of release, by automatic updates where possible (A6.4.1, A6.4.2).
- But: 3 devices haven't checked in for 30+ days.
Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].
What Microsoft 365 can't show: Intune shows which Windows release each computer runs and when it last checked in, not when updates were installed.
Write this answer for Northwind Traders
High-risk and critical application updates are installed within 14 days of release, by automatic updates where possible (A6.5.1, A6.5.2).
Applications update automatically where they can (Microsoft 365 Apps, web browsers and [other software]). Updates that can't install automatically are applied within 14 days of release by [process or tool].
What Microsoft 365 can't show: Microsoft 365 doesn't see application versions on devices.
Write this answer for Northwind Traders
User access control
FailAccounts are created through a process, are unique to a person, hold only the access the job needs, are removed when people leave, use separate accounts for administration, strong passwords and MFA on every cloud service.
A user account is created only after a request has been approved and recorded.
New accounts are created only after a request from [manager or HR] is approved by [role], recorded in [ticket system].
What Microsoft 365 can't show: A process Microsoft 365 doesn't show. The directory audit log records who created each account.
Write this answer for Northwind Traders
User and administrator accounts are each tied to a person: no shared sign-ins.
- All 3 shared mailboxes block sign-in.
Each person signs in to Microsoft 365 with their own named account. Shared mailboxes can't be signed in to directly; people reach them through their own accounts. All 3 shared mailboxes block sign-in.
What Microsoft 365 can't show: Judged from whether shared mailboxes can be signed in to. Check devices and other systems for shared logins.
Change this answer
Accounts of people who have left are disabled or deleted promptly, and no account sits unused.
- 4 accounts inactive for 90+ days or never used.
- hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
- sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
- thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
- g#EXT#@northwindtraders.example: Guest, never signed in, created ?
Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID (needs Entra ID P1 for last sign-in dates). Describe the leavers process in the answer.
Change this answer
Staff have the access their current role needs and no more, through role-based groups.
Access to files and systems is given through role-based groups, approved by [role], and changed when people move roles. [Access is reviewed every 12 months.]
What Microsoft 365 can't show: A process Microsoft 365 doesn't show; the group membership and admin role reports help review it.
Write this answer for Northwind Traders
Administrator access is granted only after approval, to a named person, and recorded.
Administrator access is given only after approval by [role], to a separate named admin account, and is recorded in [ticket system or register].
What Microsoft 365 can't show: A process Microsoft 365 doesn't show.
Write this answer for Northwind Traders
Administration is done from separate admin accounts that aren't used for email, browsing or everyday work (A7.6, A7.7).
- 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
What Microsoft 365 can't show: Judged from Microsoft 365 admin role holders: an admin account with a licence or a mailbox looks like an everyday account. Add local and domain administrators on devices and servers.
Change this answer
The organisation knows which accounts hold administrator access (A7.8) and reviews the list regularly (A7.9).
- 2 Global Administrators.
- Accounts holding privileged roles
- 4
- Admins with no MFA policy
- 1
- Admins with no MFA method registered
- 2
- 1 guest with admin roles.
- g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
- 1 app with privileged roles.
- Some app: App holding Exchange Administrator
Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →
Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.
What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; describe how often the list is reviewed and by whom.
Change this answer
Passwords are protected from brute-force guessing (A7.10: MFA, throttling or lockout) and their quality is managed technically (A7.11: MFA, 12 characters, or 8 characters with a deny list).
- Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.
Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.
What Microsoft 365 can't show: Microsoft Entra ID's defaults (8 characters, a banned password list and smart lockout) aren't read from the tenant. Add devices, servers and other systems that take passwords.
Change this answer
When a password or account may be compromised, it's reset and the account checked promptly.
If an account may be compromised, [IT provider] resets the password, signs the account out of every session, checks its MFA methods and inbox rules, and reviews its sign-ins. Staff report concerns to [contact].
What Microsoft 365 can't show: A process Microsoft 365 doesn't show; Entra ID Protection's risk detections support it.
Write this answer for Northwind Traders
Every cloud service in use offers MFA, or is linked to one that does; any that don't are listed (A7.15).
All cloud services in use offer multi-factor authentication: Microsoft 365 (through Microsoft Entra ID) and [other cloud services]. [Or list any that don't offer it.]
What Microsoft 365 can't show: Microsoft 365 offers MFA through Entra ID. List the other cloud services and check each.
Write this answer for Northwind Traders
Every administrator account on every cloud service uses MFA with a password of at least 8 characters. The assessment fails on a No.
- 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
- But: 1 admin without MFA, and 1 whose registration isn't known.
- Accounts holding privileged roles
- 4
- Admins with no MFA policy
- 1
- Admins with no MFA method registered
- 2
Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
What Microsoft 365 can't show: Judged for Microsoft 365 and Entra ID admin roles, from Conditional Access enforcement with named break-glass accounts allowed. Add administrators of other cloud services.
Change this answer
Every user of every cloud service uses MFA with a password of at least 8 characters. The assessment fails on a No.
- Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
- But: 14 users without MFA.
- Users with an MFA method registered
- 62.2% of 37
- Accounts covered by an enforced MFA policy
- 36 of 36
Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins from Conditional Access enforcement (or Security Defaults), with named break-glass accounts allowed. Add other cloud services.
Change this answer
Malware protection
Your evidenceEvery computer, tablet and phone is protected by anti-malware software that updates and scans, or only runs approved applications from a managed store.
Each device has anti-malware software that updates itself, scans files on access and blocks malicious websites (A8.2, A8.3), or installs apps only from an approved store or allow list (A8.4, A8.5).
- But: 6 of 37 managed devices not compliant.
All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.
What Microsoft 365 can't show: Office Sentry doesn't read Microsoft Defender or anti-malware settings. Intune compliance supports the answer only if the compliance policy requires anti-malware; check the policy.
Write this answer for Northwind Traders
Answers for the form
Cyber Essentials (Danzell)The Cyber Essentials self-assessment questions Microsoft 365 helps with, by their number in the IASME portal, plus the ones about firewalls, updates and processes it can't see. Questions marked auto-fail fail the whole assessment on a No.
A5 Secure configuration 1 question
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
Inactive accounts → Microsoft 365 data from 11 Oct 2026.
Still to check: Describe the leavers process: who tells IT, and how quickly accounts are disabled.
Change this answer
A6 Security update management 1 question
Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.
Devices: operating systems → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Windows computers known to Intune or Entra ID. Add servers, macOS, phones, network devices and other software. Windows 10 needs Extended Security Updates after 14 October 2025. Router and firewall firmware counts as an operating system.
Change this answer
A7 User access control 4 questions
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
Inactive accounts → Microsoft 365 data from 11 Oct 2026.
Still to check: Describe the leavers process: who tells IT, and how quickly accounts are disabled.
Change this answer
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Microsoft 365 admin roles. Add local administrator, server and domain admin accounts.
Change this answer
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Microsoft 365 admin roles. Add local administrator, server and domain admin accounts.
Change this answer
Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.
Admins and roles → Microsoft 365 data from 11 Oct 2026.
Still to check: Add administrators of servers, firewalls and other systems, and say how the list is kept.
Change this answer
About this pack
Scope: Cyber Essentials covers every device that reaches organisational data or services, every cloud service holding the organisation's data, and home workers' devices. Microsoft 365 is one cloud service in that scope, so a Pass here is evidence for the form, not the whole answer.
The answers must be approved by a board member or the business owner before submission.
Requirements: Cyber Essentials: Requirements for IT Infrastructure v3.3 (NCSC and IASME, April 2026) and IASME question set Danzell, version 16 (April 2026), for assessments bought from 27 April 2026. Requirements paraphrased from the NCSC and IASME Cyber Essentials documents; question numbers from IASME's self-assessment preparation booklet, checked 10 October 2026. IASME publishes a new question set most Aprils: check the portal's numbers before submitting. Source
Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .