Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

Essential Eight (Australia)

Northwind Traders · northwindtraders.onmicrosoft.com

The eight strategies at Maturity Level One: admin privileges, operating system patching and MFA judged from Microsoft 365, the rest as text to complete from Intune or Group Policy.

Not ready

Northwind Traders has 3 controls to fix before reaching Maturity Level One.

Judged from Microsoft 365 data collected ; 5 controls need evidence Microsoft 365 can't show.

Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal.

Fix these first

3 controls
  1. 1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.

    Fix: Remove admin roles from guest accounts. See the rows →

  2. 5 of 36 Windows computers past end of support. For example LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.

    Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release. See the rows →

  3. Enforced by Require MFA for all users, with 1 exclusion to review. For example breakglass@northwindtraders.example: Excluded from "Require MFA for all users".

    Fix: Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. See the rows →

Prevent malware running

Your evidence

Only approved programs run, applications are patched, Office macros are controlled and applications hardened.

Your evidence
1 Application control

Only approved programs, scripts and installers can run on workstations, including from user folders.

Application control ([App Control for Business, AppLocker or product]) lets only approved programs, scripts and installers run on [workstations and servers], including from user profile and temporary folders. Blocked attempts are logged and reviewed by [team].

What Microsoft 365 can't show: All of this. Answer from Intune, Group Policy or the tool that sets it.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
2 Patch applications

Internet-facing services, browsers, Office, PDF software and email clients are patched promptly, and unsupported applications are removed.

Applications update automatically where they can (Microsoft 365 Apps, web browsers and [other software]). Updates that can't install automatically are applied within 14 days of release by [process or tool].

What Microsoft 365 can't show: All of this. Answer from Intune, Group Policy or the tool that sets it.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
3 Configure Microsoft Office macro settings

Macros are blocked for users who don't need them, macros from the internet are blocked, and users can't change the settings.

Microsoft Office macros are [blocked for all users, or allowed only for (group) from trusted locations or signed by a trusted publisher], macros in files from the internet are blocked, and users can't change these settings. This is set by [Intune or Group Policy].

What Microsoft 365 can't show: All of this. Answer from Intune, Group Policy or the tool that sets it.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
4 User application hardening

Browsers don't process Java or ads from the internet, and users can't change browser security settings.

Web browsers block Java and web advertisements from the internet and don't process them, Microsoft Office blocks OLE packages, PowerShell 2.0 is removed, and users can't change these settings. This is set by [Intune or Group Policy].

What Microsoft 365 can't show: All of this. Answer from Intune, Group Policy or the tool that sets it.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Limit the extent of incidents

Fail

Admin privileges are few and separate, operating systems are patched, and everyone uses MFA.

Fail
5 Restrict administrative privileges

Privileged access is validated when first asked for, limited to what's needed, held by separate accounts that don't read email or browse the web, and removed when it's no longer needed.

  • 2 Global Administrators.
  • Cloud-only tenant: no accounts are synced from on-premises AD.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2
Gaps
  • 1 guest with admin roles.
  • g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
  • 1 app with privileged roles.
  • Some app: App holding Exchange Administrator

Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →

Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

What Microsoft 365 can't show: Judged from Microsoft 365 and Entra ID admin roles. Add local and server admins.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
6 Patch operating systems

Operating systems are patched promptly and versions no longer supported by the vendor are replaced.

  • But: 3 devices haven't checked in for 30+ days.
Computers managed by Intune
36
Of which encrypted
32
Windows computers out of support
5
Reaching end of support within 90 days
20
Not compliant
6
Gaps
  • 5 of 36 Windows computers past end of support.
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • and 20 more

Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. See the rows →

Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.

What Microsoft 365 can't show: Judged from the Windows versions Intune reports. Add servers and devices it doesn't manage.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
7 Multi-factor authentication

Users authenticate with MFA to online services holding sensitive data, and admins use phishing-resistant MFA at higher maturity levels.

  • But: 2 admins without a phishing-resistant method.
  • But: 3 people can only use a text or call as a second factor.
Users with an MFA method registered
62.2% of 37
Accounts covered by an enforced MFA policy
36 of 36
Gaps
  • Enforced by Require MFA for all users, with 1 exclusion to review.
  • breakglass@northwindtraders.example: Excluded from "Require MFA for all users"
  • 1 admin not covered by MFA.
  • breakglass@northwindtraders.example: Global Administrator: excluded from Require MFA for all users
  • Legacy authentication is allowed.
  • No enabled policy blocks legacy authentication for all users

Fix: Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts. See the rows →

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins. Add other online services.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Recover data and availability

Your evidence

Backups are taken, kept and tested, and can't be changed or deleted by ordinary accounts.

Your evidence
8 Regular backups

Backups of data, applications and settings are made, kept, protected from change and deletion, and restores are tested.

Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].

What Microsoft 365 can't show: Microsoft 365 doesn't back itself up for this purpose; describe the backup of Microsoft 365 too.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

About this pack

Maturity Level One is met only when all eight strategies meet it. Higher levels add requirements (such as phishing-resistant MFA and 48-hour patching) this pack doesn't judge.

Requirements: ASD Essential Eight Maturity Model, Maturity Level One. Strategies are ASD's, numbered in their usual order; requirements are paraphrased. Check the current maturity model on cyber.gov.au before an assessment. Source

Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .