Skip to Content
PurviewPSPF Control Mapping
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
---
name: PSPF Control Mapping
description: Maps your Microsoft 365 security controls to the Australian PSPF and Essential Eight, then reports a prioritised gap list.
---

# PSPF Control Mapping

> **TL;DR:** This skill inspects your Microsoft 365 tenant settings read-only, lines them up against the Australian Protective Security Policy Framework and Essential Eight, and reports a clear gap list with a risk score.

## How does PSPF control mapping work across Microsoft Purview and Microsoft Entra?

The Protective Security Policy Framework (PSPF) directs Australian Commonwealth entities to implement the Essential Eight at Maturity Level 2 as a baseline. This skill reads configuration signals from Microsoft Entra ID, Microsoft Purview, Exchange Online, Microsoft Teams and Microsoft Defender XDR, then aligns each signal to the relevant Essential Eight pillar and Information Security Manual (ISM) control. It produces an evidence-backed mapping so you can see, control by control, where your modern cloud tenant already meets the framework and where gaps remain.

## When should you run this skill?

- "Show me how our Microsoft 365 tenant maps to the PSPF and Essential Eight."
- "Which Essential Eight controls are we failing at Maturity Level 2?"
- "Give me a gap list before our IRAP assessment."
- "Map our Microsoft Entra MFA and admin settings to the relevant ISM controls."
- "Where are our biggest protective security gaps in Microsoft Purview?"
- "Prepare evidence of our Essential Eight posture for an audit."
- "What's our overall PSPF readiness risk score right now?"

## How this skill works, step by step

1. Read tenant identity settings from Microsoft Entra ID, including MFA registration, Conditional Access policies and privileged role assignments.
2. Inspect Microsoft Entra Privileged Identity Management to confirm just-in-time and time-bound administrative access.
3. Collect Microsoft Purview signals covering data protection, retention and Compliance Manager Essential Eight assessment scores.
4. Read Microsoft Defender XDR and Microsoft Defender Vulnerability Management posture for patching, application control and user application hardening.
5. Inspect Exchange Online and Microsoft Teams configuration for macro, attachment and external collaboration controls.
6. Align each collected signal to its Essential Eight pillar and the mapped ISM control reference.
7. Mark every control as Met, Partial or Gap against PSPF Maturity Level 2 expectations.
8. Derive a risk score by weighting each unmet control by its maturity-level severity and the sensitivity of the data it protects, then averaging across all eight pillars.
9. Produce the mapping table, the gap list and an overall readiness score.

## Output format

The skill returns a control mapping table, followed by a summary of the highest-priority gaps.

| Essential Eight pillar | ISM reference | PSPF Maturity Level 2 status | Risk | Evidence |
| --- | --- | --- | --- | --- |
| Multifactor authentication | ISM-1173 | Partial | High | MFA enforced for admins, not all users |
| Restrict administrative privileges | ISM-1883 | Met | Low | PIM just-in-time access configured |
| Patch applications | ISM-1690 | Gap | High | No fortnightly vulnerability scan evidence |

Summary of key findings:

- Overall PSPF readiness risk score: derived from weighted unmet controls across all eight pillars.
- Highest-priority gaps are listed first, with the mapped ISM control and remediation pointer.
- Each row links its status to the specific tenant setting that was read as evidence.

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| Conditional Access and MFA inspection | Microsoft Entra ID P1 |
| Privileged Identity Management read | Microsoft Entra ID P2 |
| Compliance Manager Essential Eight templates | Microsoft 365 E5 Compliance |
| Defender Vulnerability Management posture | Microsoft Defender Vulnerability Management |

### Least-privilege roles

- Global Reader
- Security Reader
- Compliance Administrator (read-only use only)

### Microsoft Graph permissions (read-only)

- `Policy.Read.All` — reads Conditional Access and authentication method policies.
- `RoleManagement.Read.Directory` — reads privileged role assignments and PIM eligibility.
- `UserAuthenticationMethod.Read.All` — reads MFA registration state across users.
- `SecurityEvents.Read.All` — reads Microsoft Defender XDR posture and alerts.
- Compliance Manager Essential Eight scores are read via the Microsoft Purview portal rather than Microsoft Graph.

## Scope and safety

This skill is read-only by default and changes no tenant configuration.

This skill does NOT:

- Modify, create or delete any Conditional Access policy, role assignment or Purview configuration.
- Remediate gaps or apply any Essential Eight control on your behalf.
- Access mailbox, file or message content beyond configuration metadata.
- Submit or alter any IRAP or Compliance Manager assessment record.

## Sources and compliance

- [Microsoft ACSC Essential Eight overview](https://learn.microsoft.com/en-us/compliance/anz/e8-overview)
- [Protective Security Policy Framework](https://www.protectivesecurity.gov.au/)
- [ASD Essential Eight Maturity Model](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight/essential-eight-maturity-model)
- Maps to all eight Essential Eight pillars and their associated ISM controls (for example ISM-1173, ISM-1690, ISM-1883) at PSPF Maturity Level 2.
- Output in Australian English.
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the panel above.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions below.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

PSPF Control Mapping

TL;DR: This skill inspects your Microsoft 365 tenant settings read-only, lines them up against the Australian Protective Security Policy Framework and Essential Eight, and reports a clear gap list with a risk score.

How does PSPF control mapping work across Microsoft Purview and Microsoft Entra?

The Protective Security Policy Framework (PSPF) directs Australian Commonwealth entities to implement the Essential Eight at Maturity Level 2 as a baseline. This skill reads configuration signals from Microsoft Entra ID, Microsoft Purview, Exchange Online, Microsoft Teams and Microsoft Defender XDR, then aligns each signal to the relevant Essential Eight pillar and Information Security Manual (ISM) control. It produces an evidence-backed mapping so you can see, control by control, where your modern cloud tenant already meets the framework and where gaps remain.

When should you run this skill?

  • “Show me how our Microsoft 365 tenant maps to the PSPF and Essential Eight.”
  • “Which Essential Eight controls are we failing at Maturity Level 2?”
  • “Give me a gap list before our IRAP assessment.”
  • “Map our Microsoft Entra MFA and admin settings to the relevant ISM controls.”
  • “Where are our biggest protective security gaps in Microsoft Purview?”
  • “Prepare evidence of our Essential Eight posture for an audit.”
  • “What’s our overall PSPF readiness risk score right now?”

How this skill works, step by step

  1. Read tenant identity settings from Microsoft Entra ID, including MFA registration, Conditional Access policies and privileged role assignments.
  2. Inspect Microsoft Entra Privileged Identity Management to confirm just-in-time and time-bound administrative access.
  3. Collect Microsoft Purview signals covering data protection, retention and Compliance Manager Essential Eight assessment scores.
  4. Read Microsoft Defender XDR and Microsoft Defender Vulnerability Management posture for patching, application control and user application hardening.
  5. Inspect Exchange Online and Microsoft Teams configuration for macro, attachment and external collaboration controls.
  6. Align each collected signal to its Essential Eight pillar and the mapped ISM control reference.
  7. Mark every control as Met, Partial or Gap against PSPF Maturity Level 2 expectations.
  8. Derive a risk score by weighting each unmet control by its maturity-level severity and the sensitivity of the data it protects, then averaging across all eight pillars.
  9. Produce the mapping table, the gap list and an overall readiness score.

Output format

The skill returns a control mapping table, followed by a summary of the highest-priority gaps.

Essential Eight pillarISM referencePSPF Maturity Level 2 statusRiskEvidence
Multifactor authenticationISM-1173PartialHighMFA enforced for admins, not all users
Restrict administrative privilegesISM-1883MetLowPIM just-in-time access configured
Patch applicationsISM-1690GapHighNo fortnightly vulnerability scan evidence

Summary of key findings:

  • Overall PSPF readiness risk score: derived from weighted unmet controls across all eight pillars.
  • Highest-priority gaps are listed first, with the mapped ISM control and remediation pointer.
  • Each row links its status to the specific tenant setting that was read as evidence.

Licensing and permissions

Licences and add-ons

Capability usedMinimum licence
Conditional Access and MFA inspectionMicrosoft Entra ID P1
Privileged Identity Management readMicrosoft Entra ID P2
Compliance Manager Essential Eight templatesMicrosoft 365 E5 Compliance
Defender Vulnerability Management postureMicrosoft Defender Vulnerability Management

Least-privilege roles

  • Global Reader
  • Security Reader
  • Compliance Administrator (read-only use only)

Microsoft Graph permissions (read-only)

  • Policy.Read.All — reads Conditional Access and authentication method policies.
  • RoleManagement.Read.Directory — reads privileged role assignments and PIM eligibility.
  • UserAuthenticationMethod.Read.All — reads MFA registration state across users.
  • SecurityEvents.Read.All — reads Microsoft Defender XDR posture and alerts.
  • Compliance Manager Essential Eight scores are read via the Microsoft Purview portal rather than Microsoft Graph.

Scope and safety

This skill is read-only by default and changes no tenant configuration.

This skill does NOT:

  • Modify, create or delete any Conditional Access policy, role assignment or Purview configuration.
  • Remediate gaps or apply any Essential Eight control on your behalf.
  • Access mailbox, file or message content beyond configuration metadata.
  • Submit or alter any IRAP or Compliance Manager assessment record.

Sources and compliance


Licensed under CC BY 4.0  by Educ4te .

Last updated on