SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
---
name: Essential Eight ML3 Uplift Planner
description: Assess current Essential Eight maturity across all eight controls and produce a prioritised, read-only plan to uplift from Maturity Level 2 to Level 3.
---
# Essential Eight ML3 Uplift Planner
> **TL;DR:** This skill reviews your current Essential Eight posture across all eight mitigation strategies and produces a prioritised, evidence-based plan to lift each control from Maturity Level 2 to Maturity Level 3.
## What is the Essential Eight Maturity Model uplift?
The Essential Eight is the Australian Signals Directorate (ASD) baseline of eight mitigation strategies, each assessed against three maturity levels. Moving from Maturity Level 2 to Maturity Level 3 hardens controls against adaptive adversaries who actively target an organisation. In a modern Microsoft 365 tenant, the relevant evidence lives across Microsoft Entra ID, Microsoft Intune, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management, Microsoft Purview, and Microsoft Sentinel. This skill correlates that telemetry against the ASD and Microsoft Learn maturity guidance to find the gaps that block a Level 3 rating.
## When should you run this skill?
- "Show me where we sit against Essential Eight Maturity Level 3 today."
- "What is blocking us from moving from ML2 to ML3?"
- "Build a prioritised Essential Eight uplift roadmap for the board."
- "Which of the eight controls are furthest from Maturity Level 3?"
- "We have an IRAP assessment coming up; gap-assess our Essential Eight posture."
- "Map our current MFA, patching, and application control settings to the ASD maturity model."
- "Give me a read-only Essential Eight scorecard before our annual review."
## How this skill works, step by step
1. Confirm the target maturity level (Level 3) and the assessment scope across the eight controls: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multifactor authentication, and regular backups.
2. Inspect Microsoft Entra ID for MFA coverage, phishing-resistant authentication strengths, Conditional Access policies, and privileged role assignments through Microsoft Entra Privileged Identity Management.
3. Read Microsoft Intune configuration and compliance policies to evaluate Windows Defender Application Control, Microsoft Office macro restrictions, and user application hardening baselines.
4. Query Microsoft Defender Vulnerability Management and Microsoft Defender for Endpoint for patch latency on operating systems and applications, plus the presence of unsupported software.
5. Review backup configuration and retention controls to confirm restoration testing and that only break-glass accounts can modify or delete backups.
6. Compare each observed setting against the documented Maturity Level 3 requirement and record a per-control status of Met, Partial, or Not Met.
7. Derive a risk score per control: weight each unmet Level 3 requirement by adversary impact and exposure, then roll the weighted gaps into a 0-100 control score and an overall tenant score.
8. Rank remediation items by risk score and implementation effort so the highest-impact, lowest-effort uplift actions surface first.
9. Produce the prioritised uplift plan with control mappings, evidence references, and recommended Microsoft remediation actions.
## Output format
The skill returns a per-control scorecard followed by a prioritised remediation summary. Each row maps an Essential Eight control to its current status, the Level 3 gap, and a risk-weighted priority.
| Essential Eight control | Current level | ML3 status | Key gap | Risk score | Priority |
| --- | --- | --- | --- | --- | --- |
| Multifactor authentication | ML2 | Partial | Phishing-resistant MFA not enforced for all privileged access | 82 | High |
| Patch applications | ML2 | Not Met | Critical application patches exceed 48-hour window | 76 | High |
| Restrict administrative privileges | ML2 | Partial | Privileged access not fully managed via just-in-time activation | 64 | Medium |
| Regular backups | ML3 | Met | Restoration testing evidenced and backups immutable | 12 | Low |
Summary of the assessment:
- Overall tenant maturity is reported as the lowest control level, in line with ASD scoring guidance.
- Each gap links to the specific Maturity Level 3 requirement and the Microsoft control that satisfies it.
- Remediation items are ordered by risk score then effort, giving a ready-to-action uplift roadmap.
- Controls already at Level 3 are listed with the evidence that confirms the rating.
## Licensing and permissions
### Licences and add-ons
| Capability used | Minimum licence |
| --- | --- |
| Conditional Access and phishing-resistant authentication strengths | Microsoft Entra ID P1 |
| Privileged Identity Management for administrative privilege review | Microsoft Entra ID P2 |
| Application control and macro hardening via configuration policies | Microsoft Intune Plan 1 |
| Vulnerability and patch posture telemetry | Microsoft Defender Vulnerability Management (with Microsoft Defender for Endpoint Plan 2) |
| Continuous Essential Eight assessment templates | Microsoft Purview Compliance Manager (Microsoft 365 E5 Compliance) |
### Least-privilege roles
- Global Reader (read-only visibility across Microsoft Entra ID and Microsoft 365 configuration)
- Security Reader (read-only access to Microsoft Defender XDR and security posture)
- Intune Read Only Operator (read-only access to device configuration and compliance policies)
### Microsoft Graph permissions (read-only)
- `Policy.Read.All` — reads Conditional Access and authentication method policies that underpin the MFA control.
- `RoleManagement.Read.Directory` — reads privileged role assignments and Privileged Identity Management eligibility for the restrict administrative privileges control.
- `DeviceManagementConfiguration.Read.All` — reads Microsoft Intune configuration profiles for application control, macro settings, and user application hardening.
- `SecurityEvents.Read.All` — reads Microsoft Defender security and vulnerability signals used to assess patch posture.
- Patch latency detail and Compliance Manager scoring are read through the Microsoft Defender and Microsoft Purview portals rather than Microsoft Graph, so no additional Graph scopes are invented for them.
## Scope and safety
This skill is read-only by default. It inspects configuration, policy, and posture telemetry to assess maturity and never changes tenant state.
This skill does NOT:
- Modify Conditional Access, Intune, patching, or backup configuration.
- Create, elevate, or remove privileged role assignments.
- Deploy patches, application control rules, or remediation actions on its behalf.
- Export, move, or alter any backup data or user content.
## Sources and compliance
- [ASD Essential Eight Maturity Model](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight/essential-eight-maturity-model) — the authoritative definition of the three maturity levels for all eight controls.
- [ACSC Essential Eight implementation guidance for Microsoft (Microsoft Learn)](https://learn.microsoft.com/en-us/compliance/anz/e8-overview) — maps each Essential Eight control and maturity level to Microsoft 365 capabilities and ISM controls.
- Maps to all eight Essential Eight mitigation strategies and to the related Information Security Manual (ISM) controls referenced in the Microsoft Learn maturity mappings, such as ISM-1690 and ISM-1704 for patching.
- Output in Australian English.
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the panel above. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions below.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Essential Eight ML3 Uplift Planner
TL;DR: This skill reviews your current Essential Eight posture across all eight mitigation strategies and produces a prioritised, evidence-based plan to lift each control from Maturity Level 2 to Maturity Level 3.
What is the Essential Eight Maturity Model uplift?
The Essential Eight is the Australian Signals Directorate (ASD) baseline of eight mitigation strategies, each assessed against three maturity levels. Moving from Maturity Level 2 to Maturity Level 3 hardens controls against adaptive adversaries who actively target an organisation. In a modern Microsoft 365 tenant, the relevant evidence lives across Microsoft Entra ID, Microsoft Intune, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management, Microsoft Purview, and Microsoft Sentinel. This skill correlates that telemetry against the ASD and Microsoft Learn maturity guidance to find the gaps that block a Level 3 rating.
When should you run this skill?
- “Show me where we sit against Essential Eight Maturity Level 3 today.”
- “What is blocking us from moving from ML2 to ML3?”
- “Build a prioritised Essential Eight uplift roadmap for the board.”
- “Which of the eight controls are furthest from Maturity Level 3?”
- “We have an IRAP assessment coming up; gap-assess our Essential Eight posture.”
- “Map our current MFA, patching, and application control settings to the ASD maturity model.”
- “Give me a read-only Essential Eight scorecard before our annual review.”
How this skill works, step by step
- Confirm the target maturity level (Level 3) and the assessment scope across the eight controls: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multifactor authentication, and regular backups.
- Inspect Microsoft Entra ID for MFA coverage, phishing-resistant authentication strengths, Conditional Access policies, and privileged role assignments through Microsoft Entra Privileged Identity Management.
- Read Microsoft Intune configuration and compliance policies to evaluate Windows Defender Application Control, Microsoft Office macro restrictions, and user application hardening baselines.
- Query Microsoft Defender Vulnerability Management and Microsoft Defender for Endpoint for patch latency on operating systems and applications, plus the presence of unsupported software.
- Review backup configuration and retention controls to confirm restoration testing and that only break-glass accounts can modify or delete backups.
- Compare each observed setting against the documented Maturity Level 3 requirement and record a per-control status of Met, Partial, or Not Met.
- Derive a risk score per control: weight each unmet Level 3 requirement by adversary impact and exposure, then roll the weighted gaps into a 0-100 control score and an overall tenant score.
- Rank remediation items by risk score and implementation effort so the highest-impact, lowest-effort uplift actions surface first.
- Produce the prioritised uplift plan with control mappings, evidence references, and recommended Microsoft remediation actions.
Output format
The skill returns a per-control scorecard followed by a prioritised remediation summary. Each row maps an Essential Eight control to its current status, the Level 3 gap, and a risk-weighted priority.
| Essential Eight control | Current level | ML3 status | Key gap | Risk score | Priority |
|---|---|---|---|---|---|
| Multifactor authentication | ML2 | Partial | Phishing-resistant MFA not enforced for all privileged access | 82 | High |
| Patch applications | ML2 | Not Met | Critical application patches exceed 48-hour window | 76 | High |
| Restrict administrative privileges | ML2 | Partial | Privileged access not fully managed via just-in-time activation | 64 | Medium |
| Regular backups | ML3 | Met | Restoration testing evidenced and backups immutable | 12 | Low |
Summary of the assessment:
- Overall tenant maturity is reported as the lowest control level, in line with ASD scoring guidance.
- Each gap links to the specific Maturity Level 3 requirement and the Microsoft control that satisfies it.
- Remediation items are ordered by risk score then effort, giving a ready-to-action uplift roadmap.
- Controls already at Level 3 are listed with the evidence that confirms the rating.
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence |
|---|---|
| Conditional Access and phishing-resistant authentication strengths | Microsoft Entra ID P1 |
| Privileged Identity Management for administrative privilege review | Microsoft Entra ID P2 |
| Application control and macro hardening via configuration policies | Microsoft Intune Plan 1 |
| Vulnerability and patch posture telemetry | Microsoft Defender Vulnerability Management (with Microsoft Defender for Endpoint Plan 2) |
| Continuous Essential Eight assessment templates | Microsoft Purview Compliance Manager (Microsoft 365 E5 Compliance) |
Least-privilege roles
- Global Reader (read-only visibility across Microsoft Entra ID and Microsoft 365 configuration)
- Security Reader (read-only access to Microsoft Defender XDR and security posture)
- Intune Read Only Operator (read-only access to device configuration and compliance policies)
Microsoft Graph permissions (read-only)
Policy.Read.All— reads Conditional Access and authentication method policies that underpin the MFA control.RoleManagement.Read.Directory— reads privileged role assignments and Privileged Identity Management eligibility for the restrict administrative privileges control.DeviceManagementConfiguration.Read.All— reads Microsoft Intune configuration profiles for application control, macro settings, and user application hardening.SecurityEvents.Read.All— reads Microsoft Defender security and vulnerability signals used to assess patch posture.- Patch latency detail and Compliance Manager scoring are read through the Microsoft Defender and Microsoft Purview portals rather than Microsoft Graph, so no additional Graph scopes are invented for them.
Scope and safety
This skill is read-only by default. It inspects configuration, policy, and posture telemetry to assess maturity and never changes tenant state.
This skill does NOT:
- Modify Conditional Access, Intune, patching, or backup configuration.
- Create, elevate, or remove privileged role assignments.
- Deploy patches, application control rules, or remediation actions on its behalf.
- Export, move, or alter any backup data or user content.
Sources and compliance
- ASD Essential Eight Maturity Model — the authoritative definition of the three maturity levels for all eight controls.
- ACSC Essential Eight implementation guidance for Microsoft (Microsoft Learn) — maps each Essential Eight control and maturity level to Microsoft 365 capabilities and ISM controls.
- Maps to all eight Essential Eight mitigation strategies and to the related Information Security Manual (ISM) controls referenced in the Microsoft Learn maturity mappings, such as ISM-1690 and ISM-1704 for patching.
- Output in Australian English.