Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

Cyber Essentials

Northwind Traders · northwindtraders.onmicrosoft.com

The five Cyber Essentials control themes, judged from Microsoft 365 data as an assessor would: any gap is a Fail. Fix the failing controls, write the evidence Microsoft 365 can't show, then copy the answers into the IASME portal.

Not ready

Northwind Traders has 4 controls to fix before applying for Cyber Essentials.

Judged from Microsoft 365 data collected ; 19 controls need evidence Microsoft 365 can't show.

No data from 12 July 2026: the oldest data held is from 6 September 2026.

Fix before you apply

6 controls
  1. Legacy authentication is allowed. No enabled policy blocks legacy authentication for all users.

    Fix: Block legacy authentication. See the rows →

  2. 5 of 36 Windows computers past end of support. For example LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.

    Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release. See the rows →

  3. 4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.

    Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →

  4. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

    Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →

  5. 1 disabled account still licensed. For example robert.hughes@northwindtraders.example: Disabled, holding 1 licence.

    Fix: Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes. See the rows →

  6. 1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.

    Fix: Remove admin roles from guest accounts. See the rows →

Firewalls

Your evidence

Every device and network in scope sits behind a firewall that blocks unauthenticated inbound connections by default, with changed passwords, reviewed rules and no administration from the internet.

Your evidence
A4.1 A firewall at every boundary with the internet

A boundary firewall (or the router's firewall) protects each internet connection, and home workers are protected by the firewall on their device.

A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.

What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A4.1.1 Software firewalls on every computer and server

The built-in firewall is turned on for every laptop, desktop and server.

The built-in software firewall (Microsoft Defender Firewall on Windows, the macOS firewall on Macs) is turned on for all computers and servers [and enforced by Intune policy].

What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A4.2 Default firewall passwords changed

The default administrator password of every router and firewall was changed to a strong one.

The default administrator passwords on all firewalls and routers were changed when they were installed, to [unique passwords of at least 12 characters, kept in a password manager].

What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A4.6 Firewall rules reviewed in the last 12 months

Inbound rules are reviewed and removed when no longer needed, at least yearly.

Firewall rules are reviewed [every 12 months] by [IT provider], and rules that are no longer needed are removed. The last review was on [date].

What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A4.7 Unauthenticated inbound connections blocked by default

The firewall blocks inbound connections unless an approved, documented rule allows one (A4.8).

Firewalls block all inbound connections by default. [No inbound connections are allowed.] or [Each allowed inbound connection is documented, with its business need approved by (role).]

What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A4.9 No firewall administration from the internet

The firewall's administration interface can't be reached from the internet, or only with MFA or from an allow list of trusted addresses with a documented need (A4.10, A4.11).

The firewall's administration interface can't be reached from the internet. [Or: remote administration is limited to (trusted IP addresses) and protected by multi-factor authentication.]

What Microsoft 365 can't show: Firewalls aren't part of Microsoft 365. Intune can enforce the Windows firewall, but reading its configuration profiles needs a permission the app doesn't hold, so answer from the firewall itself.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Secure configuration

Fail

Devices and cloud services run only the software, services and accounts they need, with default passwords changed, automatic running of files off and devices that lock.

Your evidence
A5.1 Unused software and services removed from devices

Software and services nobody uses are removed or turned off on every device.

New devices are set up from [a standard build or Windows Autopilot] without unnecessary software, and unused software and services are removed [during regular reviews by the IT provider].

What Microsoft 365 can't show: Microsoft 365 doesn't report what's installed on devices.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
A5.1 (cloud services) Unneeded sign-in protocols turned off in Microsoft 365

Services that aren't needed are turned off in cloud services too: for Microsoft 365, the legacy sign-in protocols that can't use MFA, and SMTP AUTH on mailboxes that don't send mail that way.

Gaps
  • Legacy authentication is allowed.
  • No enabled policy blocks legacy authentication for all users
  • SMTP AUTH is on for the organisation.
  • SMTP AUTH is allowed

Fix: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target. See the rows →

Legacy authentication is allowed. SMTP AUTH is on for the organisation.

What Microsoft 365 can't show: Judged from Conditional Access and Exchange Online settings.

Partly
A5.2 Only the accounts that are needed

Devices and cloud services hold only the user accounts in use: no leftover licensed-but-disabled accounts and no forgotten guest invitations.

  • No stale guest invitations.
Gaps
  • 1 disabled account still licensed.
  • robert.hughes@northwindtraders.example: Disabled, holding 1 licence

Fix: Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes (free up to 50 GB) before removing the licence. See the rows →

No stale guest invitations. 1 disabled account still licensed.

What Microsoft 365 can't show: Judged from Microsoft Entra ID accounts and guest invitations. Add local accounts on devices and servers.

Your evidence
A5.3 Default passwords changed on every device and account

Default and built-in account passwords are changed at set-up.

Default and built-in accounts on devices are turned off or given new passwords at set-up. [Local administrator passwords are managed by Windows LAPS.]

What Microsoft 365 can't show: Microsoft 365 accounts have no default password; this is about devices and built-in accounts.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A5.8 Automatic running of downloaded files turned off

AutoRun and AutoPlay are off, and downloaded files don't run without the user's say-so.

AutoPlay and AutoRun are turned off on Windows computers [by Intune policy], and downloaded files can't run without the user's permission.

What Microsoft 365 can't show: Office Sentry doesn't read device configuration profiles from Intune, so answer from the Intune policy.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A5.9 Devices lock and need a PIN, password or biometric

Every device locks after inactivity and unlocks with a password, PIN of at least six digits or biometric (A5.10), with brute-force protection.

Computers lock after [5 to 15] minutes of inactivity and need a password, PIN or Windows Hello to unlock. Phones and tablets need a PIN of at least 6 digits or biometrics [enforced by Intune].

What Microsoft 365 can't show: Office Sentry doesn't read device configuration profiles from Intune, so answer from the Intune policy.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Security update management

Fail

Every operating system and application is supported by its vendor, licensed, set to update automatically where possible, and has high-risk and critical updates installed within 14 days.

Fail
A6.1 Every operating system still supported by its vendor

All operating systems in scope receive regular security updates from their vendor; Windows 10 needs Extended Security Updates after October 2025.

Computers managed by Intune
36
Of which encrypted
32
Windows computers out of support
5
Reaching end of support within 90 days
20
Not compliant
6
Gaps
  • 5 of 36 Windows computers past end of support.
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • and 20 more

Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. See the rows →

Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.

What Microsoft 365 can't show: Judged for Windows computers known to Intune or Entra ID. macOS, Linux, phones, servers not joined to Entra ID and router or firewall firmware aren't seen.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A6.2 Every application supported and licensed

Browsers, anti-malware, email and office applications are supported versions (A6.2.1 to A6.2.4), nothing is unlicensed or unsupported (A6.3, A6.6), and any unsupported software is on a separate sub-set (A6.7).

All software in use is supported by its vendor and licensed: [browser and version], [anti-malware product and version], [email application and version] and [office applications and version]. Software that is no longer supported has been removed[, or runs on a separate sub-set outside the scope].

What Microsoft 365 can't show: Microsoft 365 doesn't report installed application versions. Intune's discovered apps would need a permission the app doesn't hold.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A6.4 Operating system updates within 14 days Auto-fail

High-risk and critical security updates for operating systems, routers and firewalls are installed within 14 days of release, by automatic updates where possible (A6.4.1, A6.4.2).

  • But: 3 devices haven't checked in for 30+ days.

Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].

What Microsoft 365 can't show: Intune shows which Windows release each computer runs and when it last checked in, not when updates were installed.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A6.5 Application updates within 14 days Auto-fail

High-risk and critical application updates are installed within 14 days of release, by automatic updates where possible (A6.5.1, A6.5.2).

Applications update automatically where they can (Microsoft 365 Apps, web browsers and [other software]). Updates that can't install automatically are applied within 14 days of release by [process or tool].

What Microsoft 365 can't show: Microsoft 365 doesn't see application versions on devices.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

User access control

Fail

Accounts are created through a process, are unique to a person, hold only the access the job needs, are removed when people leave, use separate accounts for administration, strong passwords and MFA on every cloud service.

Your evidence
A7.1 Accounts created only through an approval process

A user account is created only after a request has been approved and recorded.

New accounts are created only after a request from [manager or HR] is approved by [role], recorded in [ticket system].

What Microsoft 365 can't show: A process Microsoft 365 doesn't show. The directory audit log records who created each account.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
A7.2 Every account used by one person, with unique credentials

User and administrator accounts are each tied to a person: no shared sign-ins.

  • All 3 shared mailboxes block sign-in.

Each person signs in to Microsoft 365 with their own named account. Shared mailboxes can't be signed in to directly; people reach them through their own accounts. All 3 shared mailboxes block sign-in.

What Microsoft 365 can't show: Judged from whether shared mailboxes can be signed in to. Check devices and other systems for shared logins.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
A7.3 Leavers' accounts disabled or deleted

Accounts of people who have left are disabled or deleted promptly, and no account sits unused.

Gaps
  • 4 accounts inactive for 90+ days or never used.
  • hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
  • sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
  • thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
  • g#EXT#@northwindtraders.example: Guest, never signed in, created ?

Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →

Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.

What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID (needs Entra ID P1 for last sign-in dates). Describe the leavers process in the answer.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A7.4 Only the access the job needs

Staff have the access their current role needs and no more, through role-based groups.

Access to files and systems is given through role-based groups, approved by [role], and changed when people move roles. [Access is reviewed every 12 months.]

What Microsoft 365 can't show: A process Microsoft 365 doesn't show; the group membership and admin role reports help review it.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A7.5 A formal process for giving administrator access

Administrator access is granted only after approval, to a named person, and recorded.

Administrator access is given only after approval by [role], to a separate named admin account, and is recorded in [ticket system or register].

What Microsoft 365 can't show: A process Microsoft 365 doesn't show.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
A7.6 Separate accounts for administration

Administration is done from separate admin accounts that aren't used for email, browsing or everyday work (A7.6, A7.7).

Gaps
  • 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →

Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

What Microsoft 365 can't show: Judged from Microsoft 365 admin role holders: an admin account with a licence or a mailbox looks like an everyday account. Add local and domain administrators on devices and servers.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
A7.8 Administrator accounts tracked and reviewed

The organisation knows which accounts hold administrator access (A7.8) and reviews the list regularly (A7.9).

  • 2 Global Administrators.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2
Gaps
  • 1 guest with admin roles.
  • g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
  • 1 app with privileged roles.
  • Some app: App holding Exchange Administrator

Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →

Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.

What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; describe how often the list is reviewed and by whom.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
A7.10 Passwords protected from guessing, with quality controls

Passwords are protected from brute-force guessing (A7.10: MFA, throttling or lockout) and their quality is managed technically (A7.11: MFA, 12 characters, or 8 characters with a deny list).

  • Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.

Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.

What Microsoft 365 can't show: Microsoft Entra ID's defaults (8 characters, a banned password list and smart lockout) aren't read from the tenant. Add devices, servers and other systems that take passwords.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A7.13 A process for a compromised password or account

When a password or account may be compromised, it's reset and the account checked promptly.

If an account may be compromised, [IT provider] resets the password, signs the account out of every session, checks its MFA methods and inbox rules, and reviews its sign-ins. Staff report concerns to [contact].

What Microsoft 365 can't show: A process Microsoft 365 doesn't show; Entra ID Protection's risk detections support it.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A7.14 MFA available on every cloud service

Every cloud service in use offers MFA, or is linked to one that does; any that don't are listed (A7.15).

All cloud services in use offer multi-factor authentication: Microsoft 365 (through Microsoft Entra ID) and [other cloud services]. [Or list any that don't offer it.]

What Microsoft 365 can't show: Microsoft 365 offers MFA through Entra ID. List the other cloud services and check each.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
A7.16 MFA for every administrator of cloud services Auto-fail

Every administrator account on every cloud service uses MFA with a password of at least 8 characters. The assessment fails on a No.

  • 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
  • But: 1 admin without MFA, and 1 whose registration isn't known.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2

Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").

What Microsoft 365 can't show: Judged for Microsoft 365 and Entra ID admin roles, from Conditional Access enforcement with named break-glass accounts allowed. Add administrators of other cloud services.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
A7.17 MFA for every user of cloud services Auto-fail

Every user of every cloud service uses MFA with a password of at least 8 characters. The assessment fails on a No.

  • Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
  • But: 14 users without MFA.
Users with an MFA method registered
62.2% of 37
Accounts covered by an enforced MFA policy
36 of 36

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins from Conditional Access enforcement (or Security Defaults), with named break-glass accounts allowed. Add other cloud services.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Malware protection

Your evidence

Every computer, tablet and phone is protected by anti-malware software that updates and scans, or only runs approved applications from a managed store.

Your evidence
A8.1 Anti-malware on every computer, tablet and phone

Each device has anti-malware software that updates itself, scans files on access and blocks malicious websites (A8.2, A8.3), or installs apps only from an approved store or allow list (A8.4, A8.5).

  • But: 6 of 37 managed devices not compliant.

All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.

What Microsoft 365 can't show: Office Sentry doesn't read Microsoft Defender or anti-malware settings. Intune compliance supports the answer only if the compliance policy requires anti-malware; check the policy.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Answers for the form

Cyber Essentials (Danzell)

The Cyber Essentials self-assessment questions Microsoft 365 helps with, by their number in the IASME portal, plus the ones about firewalls, updates and processes it can't see. Questions marked auto-fail fail the whole assessment on a No.

Fill in the 21 answers marked Your input, then copy.

13 answered from Microsoft 365; 6 answered Partly or No. Parts [in brackets] still need filling in.

A2 Scope of assessment 1 question

Your input
A2.4.2 How are home and remote workers connecting to company data and services?

Home and remote workers connect over [home broadband or business-provided routers] to Microsoft 365, with multi-factor authentication. [Office systems are reached through (VPN product).]

Why: Microsoft 365 can't show this. It sees where people sign in from, not how their network connects.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

A4 Firewalls 6 questions

Your input
A4.1 Do you have firewalls at the boundaries between your networks, devices and the internet?

A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A4.1.1 Do you have software firewalls turned on for all computers, laptops and servers?

The built-in software firewall (Microsoft Defender Firewall on Windows, the macOS firewall on Macs) is turned on for all computers and servers [and enforced by Intune policy].

Why: Microsoft 365 can't show this. Office Sentry doesn't read firewall settings from Intune.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A4.2 Have you changed the default passwords on your boundary firewalls?

The default administrator passwords on all firewalls and routers were changed when they were installed, to [unique passwords of at least 12 characters, kept in a password manager].

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A4.6 Have you reviewed your firewall rules in the last 12 months?

Firewall rules are reviewed [every 12 months] by [IT provider], and rules that are no longer needed are removed. The last review was on [date].

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A4.7 Is your firewall set to allow unauthenticated inbound connections?

Firewalls block all inbound connections by default. [No inbound connections are allowed.] or [Each allowed inbound connection is documented, with its business need approved by (role).]

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Still to check: The form asks this the other way round, so the answer shown is already swapped (the hoped-for answer is No).

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A4.9 Can your boundary firewalls' settings be reached over the internet?

The firewall's administration interface can't be reached from the internet. [Or: remote administration is limited to (trusted IP addresses) and protected by multi-factor authentication.]

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Still to check: The form asks this the other way round, so the answer shown is already swapped (the hoped-for answer is No). If they can, A4.10 and A4.11 ask for the business need and MFA.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

A5 Secure configuration 4 questions

Your input
A5.1 Have you removed or turned off software and services you don't use?

New devices are set up from [a standard build or Windows Autopilot] without unnecessary software, and unused software and services are removed [during regular reviews by the IT provider].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A5.3 Have you changed the default passwords on all user and administrator accounts on your devices?

Default and built-in accounts on devices are turned off or given new passwords at set-up. [Local administrator passwords are managed by Windows LAPS.]

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A5.8 Have you turned off features that run downloaded or imported files automatically?

AutoPlay and AutoRun are turned off on Windows computers [by Intune policy], and downloaded files can't run without the user's permission.

Why: Microsoft 365 can't show this. Office Sentry doesn't read device configuration profiles.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A5.9 Do devices lock and need a PIN, password or biometric to unlock?

Computers lock after [5 to 15] minutes of inactivity and need a password, PIN or Windows Hello to unlock. Phones and tablets need a PIN of at least 6 digits or biometrics [enforced by Intune].

Why: Microsoft 365 can't show this. Office Sentry doesn't read device configuration profiles.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

A6 Security update management 3 questions

Your input
A6.2 Is all the software on your devices supported by a supplier that produces regular security updates, and licensed?

All software in use is supported by its vendor and licensed: [browser and version], [anti-malware product and version], [email application and version] and [office applications and version]. Software that is no longer supported has been removed[, or runs on a separate sub-set outside the scope].

Why: Microsoft 365 can't show this. Office Sentry doesn't see which application versions are installed.

Still to check: A6.2.1 to A6.2.4 ask for the browser, anti-malware, email and office applications with their versions.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A6.4 Are high-risk and critical updates for operating systems, routers and firewalls installed within 14 days of release? Auto-fail

Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].

Why: Microsoft 365 can't show this. Intune shows which Windows version each computer runs (see the supported systems answer), not when updates were installed.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A6.5 Are high-risk and critical updates for applications installed within 14 days of release? Auto-fail

Applications update automatically where they can (Microsoft 365 Apps, web browsers and [other software]). Updates that can't install automatically are applied within 14 days of release by [process or tool].

Why: Microsoft 365 can't show this. Office Sentry doesn't see which application versions are installed.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

A7 User access control 6 questions

Your input
A7.1 Are user accounts only created after an approval process?

New accounts are created only after a request from [manager or HR] is approved by [role], recorded in [ticket system].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A7.4 Do staff only have the access they need for their current job?

Access to files and systems is given through role-based groups, approved by [role], and changed when people move roles. [Access is reviewed every 12 months.]

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A7.5 Do you have a formal process for giving someone administrator access?

Administrator access is given only after approval by [role], to a separate named admin account, and is recorded in [ticket system or register].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A7.9 Do you review who should have administrative access regularly?

Administrator access is reviewed [quarterly] by [role] against the list of current administrators, and anyone who no longer needs it has it removed.

Why: Microsoft 365 can't show this. It shows who holds admin roles today (see the administrator access answer), not that a review happens.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A7.13 Do you have a process for when passwords or accounts may be compromised?

If an account may be compromised, [IT provider] resets the password, signs the account out of every session, checks its MFA methods and inbox rules, and reviews its sign-ins. Staff report concerns to [contact].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
A7.14 Do all of your cloud services offer multi-factor authentication?

All cloud services in use offer multi-factor authentication: Microsoft 365 (through Microsoft Entra ID) and [other cloud services]. [Or list any that don't offer it.]

Why: Microsoft 365 can't show this. It knows about Microsoft 365, which offers MFA; other cloud services need checking.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

A8 Malware protection 1 question

Your input
A8.1 Are all desktops, laptops, tablets and phones protected from malware?

All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.

Why: Microsoft 365 can't show this. Office Sentry doesn't read anti-malware settings.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

About this pack

Scope: Cyber Essentials covers every device that reaches organisational data or services, every cloud service holding the organisation's data, and home workers' devices. Microsoft 365 is one cloud service in that scope, so a Pass here is evidence for the form, not the whole answer.

The answers must be approved by a board member or the business owner before submission.

Requirements: Cyber Essentials: Requirements for IT Infrastructure v3.3 (NCSC and IASME, April 2026) and IASME question set Danzell, version 16 (April 2026), for assessments bought from 27 April 2026. Requirements paraphrased from the NCSC and IASME Cyber Essentials documents; question numbers from IASME's self-assessment preparation booklet, checked 10 October 2026. IASME publishes a new question set most Aprils: check the portal's numbers before submitting. Source

Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .