Cyber Essentials is a UK government-backed cybersecurity certification scheme. It covers five technical controls that, if implemented correctly, protect against the most common cyber attacks. Many organisations pursuing Cyber Essentials are surprised to find that a significant number of the requirements relate directly to Microsoft 365 configuration.
In a Microsoft 365 context, this applies primarily to access controls rather than traditional network firewalls. Relevant M365 settings:
Systems should be configured securely — default passwords changed, unnecessary services disabled. In Microsoft 365:
User accounts should only have the access they need. In Microsoft 365:
Malware protection must be active on all devices. In Microsoft 365:
Software must be kept up to date. In Microsoft 365:
Common Cyber Essentials failure points in Microsoft 365: Legacy authentication not blocked (question 2), Global Admin accounts used for daily tasks (question 3), Office perpetual licence (e.g. Office 2019) instead of Microsoft 365 Apps (question 5).
Cyber Essentials is self-assessed. Cyber Essentials Plus involves an external assessor who will test your controls technically — including attempting to authenticate without MFA, scanning for unpatched software, and checking that malware protection is genuinely active.
M365Clarity maps every scan finding to the relevant Cyber Essentials controls in the Compliance tab. You'll see which controls you're passing, which are failing, and exactly what needs to be fixed — with direct links to the admin centres to resolve them. It won't replace your Cyber Essentials assessment, but it'll make sure you're not failing on the Microsoft 365 side.
Connect your tenant, run a scan, and see exactly what needs attention — in plain English. Free plan available.
Scan your tenant free →Related articles