Free tool

Cyber Essentials checklist for Microsoft 365

Every Cyber Essentials requirement across the five controls. 8 of the 17 can be checked in Microsoft 365, and this shows you where. Tick them off as you go; your progress stays in this browser.

0 of 17 ready

01

Firewalls

Internet-connected devices sit behind a correctly configured firewall.

  • Confirm outside Microsoft 365: Boundary firewalls and routers are in place, default passwords are changed, and every inbound rule is approved and documented.

  • Confirm outside Microsoft 365: The software firewall is on for every laptop and other device used outside the office.

02

Secure configuration

Devices and cloud services are configured to reduce what an attacker can use.

  • Check in Microsoft 365

    • Device compliance policy coverageIntune admin centre → Devices → Compliance policies
    • Device compliance rateIntune admin centre → Reports → Device compliance
    • Unmanaged devices in the directoryEntra admin centre → Identity → Devices → All devices
  • Check in Microsoft 365

    • Device compliance requirement in Conditional AccessEntra admin centre → Protection → Conditional Access
  • Check in Microsoft 365

    • Blocking of legacy authenticationEntra admin centre → Protection → Conditional Access
    • User consent to third-party applicationsEntra admin centre → Identity → Applications → Enterprise applications → Consent and permissions
    • Application registration by non-administratorsEntra admin centre → Identity → Users → User settings
  • Confirm outside Microsoft 365: Devices have unnecessary software and accounts removed, default passwords changed, and auto-run of downloaded content disabled.

  • Confirm outside Microsoft 365: Every device requires a PIN, password or biometric to unlock, with lockout or throttling after failed attempts.

03

User access control

Only the right people have accounts, with only the access they need, protected by MFA.

  • Check in Microsoft 365

    • Multi-factor authentication registration coverageEntra admin centre → Protection → Authentication methods
    • Enforcement of multi-factor authentication for all usersEntra admin centre → Protection → Conditional Access
    • Identity baseline: security defaults or Conditional AccessEntra admin centre → Identity → Overview → Properties
  • Check in Microsoft 365

    • Administrators without registered multi-factor authenticationEntra admin centre → Identity → Roles and administrators
    • Phishing-resistant authentication for administratorsEntra admin centre → Protection → Conditional Access → Authentication strengths
  • Check in Microsoft 365

    • Number of Global AdministratorsEntra admin centre → Identity → Roles and administrators → Global Administrator
    • Privileged roles held by synchronised on-premises accountsEntra admin centre → Identity → Roles and administrators
    • Just-in-time privileged access (PIM)Entra admin centre → Identity governance → Privileged Identity Management
  • Check in Microsoft 365

    • Disabled or dormant accounts holding privileged rolesEntra admin centre → Identity → Roles and administrators
    • Dormant enabled accountsEntra admin centre → Identity → Users → All users
    • Leavers not fully offboardedMicrosoft 365 admin centre → Users → Active users → the user → Licences and apps / Mail
  • Confirm outside Microsoft 365: Joiners, movers and leavers follow an approval process, and admin accounts are used only for administration.

04

Malware protection

Malicious software is stopped from running on every device.

  • Confirm outside Microsoft 365: Anti-malware (e.g. Microsoft Defender Antivirus) is active and up to date on every device, including BYOD in scope, or application allow-listing is enforced.

  • Confirm outside Microsoft 365: Web protection blocks known malicious sites (e.g. Defender SmartScreen or network protection).

05

Security update management

Software is supported and security updates are applied promptly.

  • Check in Microsoft 365

    • Unsupported operating systems in useIntune admin centre → Devices → Windows updates / Update policies
  • Confirm outside Microsoft 365: Automatic updates are on, and critical or high-risk security updates are applied within 14 days (e.g. Intune update rings with deadlines).

  • Confirm outside Microsoft 365: All installed software is licensed and still supported by its vendor; unsupported software has been removed.

Mapping reviewed September 2026 against the NCSC's published requirements. Readiness is not certification: certification is assessed by an IASME certification body. Read the official Cyber Essentials requirements.