Frameworks change. Misconfigured Microsoft 365 tenants don’t fix themselves.

This article expands on a post originally published on LinkedIn on 25 June 2026.

Australia’s Essential Eight is being retired.

If you have spent the last few years chasing it, don’t panic. ASD is not taking MFA, patching, backups and least privilege out the back and making them retired and posting an ID Pass on the Laptop onto LinkedIn

The framework around them is changing because the environment it was written for has changed.

What ASD is changing

 

The Australian Signals Directorate intends to retire the Essential Eight within two years. It will be replaced by a broader Essentials series covering enterprise IT, cloud, operational technology and possibly agentic AI as separate areas.

Enterprise IT comes first. Cloud gets its own treatment later.

That separation tells you most of what you need to know.

The Essential Eight came from an on-premises, Windows-heavy view of enterprise IT. Cloud existed, obviously, but it was not where most businesses lived when the framework took shape.

By 2023, the maturity model was still explicitly telling organisations to disable or remove Internet Explorer 11.

That was sensible advice. Unsupported software is a risk. It also tells you what the framework was built to see.

A modern Microsoft 365 tenant has other problems: Conditional Access exclusions, stale administrator roles, weak authentication methods, excessive guest access, abandoned enterprise applications, unmanaged devices and settings that drift across a customer fleet.

You cannot cover that properly by stretching an on-premises checklist until it fits the cloud.

The controls are not the problem

 

MFA still matters. So do patching, backups, application control, least privilege and secure configuration.

The Five Eyes cyber security agencies made the same point in June 2026:

“Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy.”

Not buying the most tools. Not collecting the most framework badges.

Getting the basics right.

Frameworks are useful because they organise security thinking and give people something to measure against. They become a problem when the document starts driving the security program instead of the risk.

Documents age. Technology changes underneath them. 

The basic principles age much better.

Most Australian businesses, and worldwide, most businesses are small

 

97.3% of Australian businesses have fewer than 20 employees.

They are not miniature federal agencies. Most do not have a CISO, a security engineering team or someone sitting around interpreting maturity models.

They have an MSP. They have Microsoft 365. Quite often they have Business Premium and no clear view of whether the security features they already pay for are configured properly.

That is the actual job.

Get strong authentication working. Restrict administrative access. Remove legacy methods. Tighten external sharing. Review enterprise applications. Manage the devices. Protect the mailboxes. Make sure recovery works. Then keep checking, because the tenant will drift.

Brilliant basics, applied consistently.

There is a MASSIVE contradiction hiding in the framework conversation

 

Some vendors have built blueprint libraries around named frameworks such as Essential Eight and CIS.

Now that Essential Eight is being retired, the argument has shifted. Frameworks are only inputs, they say. Security should be built around the customer instead. 

Fair enough.

But that leaves an obvious question: if the framework was only an input, why was the operational blueprint built around the framework in the first place?

A blueprint named after a framework inherits that framework’s assumptions. It also inherits the maintenance problem when the framework moves, gets renamed or disappears.

The MSP is then left translating the replacement, rebuilding the baseline and working out what changed across every tenant.

Again.

Build the tenant baseline you can stand behind first

 

The Microsoft 365 security baseline should come first.

Essential Eight, CIS and whatever replaces them can be mapped against it afterward. We do this with Bundles. Bundles are a switch. On or Off. 

That sounds like a small distinction. We don’t think so.

One approach asks, “How do we make this tenant match the framework?”

The other asks, “What does this tenant need to be secure, supportable and maintainable?”

That’s what Microsoft MVP’s like Jonathan Edwards says – just get the Basics right, get a proper CA stack. This is the most important thing on Day 0, or Day 1…

The framework still informs the answer. It just stops pretending to be the whole answer.

Where Business Premium – Essentials fits

 

365sentri’s Business Premium – Essentials blueprint starts with the Microsoft 365 tenant which is configured basically for the Small to Medium Business.

It focuses on the most important configurations available to a Business Premium customer. Identity, administrator access, authentication, sharing, devices, email security, visibility and recovery.

Things the customer already owns. Things an MSP can actually deploy.

Things that materially improve the security of the tenant.

We compare the blueprint with the live environment and show the difference between the expected configuration and what is actually there.

Then the MSP can work through it in stages. Assess first. Agree on the changes. Remediate when the customer is ready. Keep checking for drift afterward.

It is not a claim that every Business Premium tenant has the same risk, or that one blueprint replaces every compliance obligation.

It is a practical starting point built around the platform most SMBs are actually using.

Compliance still matters where it matters

 

If a customer is contractually required to meet Essential Eight Maturity Level Two, meet it.

If a government supply chain, insurer or regulator expects a particular framework, document the requirement and prove the controls.

No argument there.

The mistake is applying that same compliance exercise to every customer and assuming the score is the security outcome.

A business can chase a framework percentage while leaving obvious Microsoft 365 risks untouched. We routinely see this.

It can also have strong practical controls that do not fit neatly into an ageing checklist.

Context still matters. Context always matters. Context in an age with overwhelming content, always matters.

What MSPs should do now

 

Do not stop the Essential Eight work already underway. ASD has said the investment remains relevant during the transition.

Do stop treating the document as the security program.

Work out which customers have a genuine Essential Eight obligation. Keep meeting it for them.

For everyone else, establish the Microsoft 365 baseline. Find the gaps that expose the tenant today. Fix those first. Keep evidence of the starting point, the changes and the current state.

When the new Essentials series lands, map it against a baseline that already exists and is already being maintained.

That is a much smaller job than rebuilding your security standard every time someone publishes a new PDF.

The framework is retiring. The work isn’t – and it never will.

 

The Essential Eight is changing because ASD knows a fixed checklist cannot keep absorbing every new technology and threat forever.

Good.

The response is not to wait two years for the replacement.

Get the basics right now. Build them around the environment you are responsible for. Prove they are working. Keep them working.

Whatever framework comes next can catch up.

Want to know where a Microsoft 365 tenant stands today?

Run an initial assessment with 365sentri. Get the Tenant Health view, Secure Score and the configuration gaps you can start acting on now.

Book a 365sentri assessment.

 

Sources:
ASD consultation on the Essentials series,
ASD retirement announcement reported by iTnews,
Five Eyes Cyber Security Agencies Statement, and
Australian small-business statistics.