Compliance / By country / Essential Eight
ACSC Essential Eight and Microsoft 365
The ACSC's prioritized eight mitigations; MFA and admin-privilege restriction map to core findings. Siemserva by Senserva maps 356+ Microsoft 365 and Entra ID checks to the areas Essential Eight emphasizes, so a scan of your tenant doubles as evidence.
What Essential Eight is
The Essential Eight is the Australian Cyber Security Centre's set of prioritized mitigation strategies. Two of the eight, multi-factor authentication and restricting administrative privileges, map directly onto Senserva's core Microsoft 365 and Entra ID findings, and application control and patching map to device and patch findings.
How Siemserva maps to Essential Eight
Essential Eight asks for strong identity, access control, and monitoring. Siemserva evidences those areas with the checks below, each ranked by Severity and checked against your own tenant:
Multi-factor authentication (42 checks)
Auth User Not MFA RegisteredAuth Microsoft Authenticator Authentication Method In Use But Not Allowed By UserAuth Password Authentication Method In Use But Not Allowed By Senserva Security ManagerAuth Passwordless Microsoft Authenticator Authentication Method In Use But Not Allowed By UserAuth Require Passwordless But Its Not Used By UserAuth Software Oath Authentication Method In Use But Not Allowed By UserPrivileged access (PIM) (34 checks)
Conditional Access (60 checks)
Device compliance (220 checks)
See every check with its Severity and remediation in the checks catalog, or the per-control detail in the control reference.
Essential Eight and Microsoft 365: common questions
Does Essential Eight apply to Microsoft 365?
ACSC Essential Eight does not name Microsoft 365 specifically, but its identity, access-control, and logging requirements are met (or missed) in your Microsoft 365 and Entra ID configuration. That is where Siemserva checks provide the evidence.
How does Siemserva map to Essential Eight?
Siemserva runs 356+ Microsoft 365 and Entra ID checks across the areas Essential Eight emphasizes, multi-factor authentication, Conditional Access, privileged access, and logging, ranks the gaps by Severity, and produces audit-ready evidence. It is evidence, not an official mapping or certification.
Is this an official Essential Eight certification?
No. Senserva is not an assessor and issues no certifications. It provides the configuration evidence, Severity ranking, and remediation that make an assessment defensible. Confirm requirements with your assessor or regulator.
More: the frameworks crosswalk, Microsoft 365 compliance by country, and the audit evidence guide.