Cyber Essentials Plus for Microsoft 365: Sample Device Testing Walkthrough
Published 7 July 2026
Conditional Access policies that pass
- MFA required for all users, all cloud apps, from all locations.
- Block legacy authentication protocols (IMAP, POP, EWS basic).
- Require compliant or hybrid-joined devices for privileged roles.
- Session controls: sign-in frequency and browser persistence limited on high-risk accounts.
Assessors will ask to see the policies applied in Azure AD (Entra) and will spot any exclusion group that carves users out of MFA. If a "break glass" account is excluded, evidence it is protected by a long random password stored in a vault.
Intune configuration profiles the assessor expects
- Windows compliance policy: BitLocker on, Defender on, minimum OS build, firewall on.
- Update ring policy: quality updates deferred no more than 7 days, feature updates within 14.
- Configuration profile: screen lock at 15 minutes, USB restrictions if you claim them.
- App protection policies for BYOD if you allow personal devices to read mail.
Defender for Endpoint evidence
Sample devices need Defender running with signatures under 24 hours old and onboarded to your tenant. Export the device inventory from the Defender portal and cross-check it against your CE Plus sample list before the audit.
Admin account separation in Entra
- Separate cloud-only admin identities (name.admin@tenant.onmicrosoft.com is common).
- No Exchange mailbox on admin accounts.
- Privileged Identity Management for just-in-time role activation is a plus, not a requirement.
- Global admin count kept under five.
The M365 evidence pack
- Conditional Access policy export (JSON or screenshot).
- Intune compliance and configuration profile summaries.
- Defender device inventory export showing sample devices as compliant.
- Entra sign-in log sample showing MFA prompts on admin accounts.
- Legacy auth report from Entra showing zero recent successful legacy sign-ins.
Non-M365 cloud services still count
Every SaaS with organisational data is in scope. Xero, GitHub, HubSpot, Slack, Docusign, LinkedIn Business Manager – MFA on all of them, admin accounts identified. Full guidance in CE Plus for SaaS companies.
Sample device day
Assessors run an authenticated vulnerability scan on the sample. On a compliant Intune-managed Windows 11 device with Defender active and recent patches, the scan is usually clean. The common surprise is a browser or Adobe Reader that slipped past the update ring. Force-run updates 48 hours before.
For the full 30-day plan see the readiness checklist, or the common failures listfor the traps to check first.
