Home About Tools Projects Guides & Blog ⚡ Hire Me ✦ Websites Contact →
Cyber Essentials Intune Microsoft 365

Cyber Essentials with Intune: A Complete Setup Guide for UK Small Businesses

Published 16 March 2026 · 12 min read · Jack Davies

If your business is going for Cyber Essentials certification - or you need it for a contract - this guide covers exactly how to meet all five technical controls using Microsoft Intune and Microsoft 365. No fluff, just the settings that matter and where to find them.

Contents
  1. What is Cyber Essentials?
  2. Which M365 licence do you need?
  3. Control 1 - Firewalls
  4. Control 2 - Secure Configuration
  5. Control 3 - User Access Control
  6. Control 4 - Malware Protection
  7. Control 5 - Patch Management
  8. Pre-submission checklist
  9. Need help with setup?

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme run by the NCSC (National Cyber Security Centre). It covers five core technical controls that protect against the most common cyber threats.

It comes in two levels:

A growing number of central government contracts, NHS frameworks, and MOD supply chain agreements now require at least Cyber Essentials as a minimum. Some insurers also offer reduced premiums for certified businesses.

Cost: Cyber Essentials certification typically costs between £300-£500 for a small business through an NCSC-approved certifying body. The IASME Consortium is one of the most commonly used for SMEs.

Which Microsoft 365 licence do you need?

Microsoft 365 Business Premium is the recommended licence for Cyber Essentials compliance. It includes everything you need:

Feature Business Basic Business Standard Business Premium
Microsoft Intune - -
Defender for Business - -
Entra ID P1 (Conditional Access) - -
BitLocker Management - -
Azure Information Protection P1 - -

If you already have Business Basic or Standard and don't want to upgrade the full estate, you can add Microsoft Defender for Business and Microsoft Intune Plan 1 as add-ons, though upgrading to Premium is usually cheaper per user once you factor in both.

Control 1 - Firewalls

Cyber Essentials requires a firewall (or equivalent boundary device) on all internet-facing connections, and a software firewall on every device.

For Windows devices managed by Intune, the Windows Defender Firewall is your software firewall. You need to confirm it's enabled on all three profiles - Domain, Private, and Public.

Intune Admin Centre path
Endpoint security Firewall Create policy Windows 10, 11, and later Windows Firewall

Set the following for each network profile (Domain, Private, Public):

For Cyber Essentials, there is no requirement to manage specific inbound/outbound rules via Intune - the assessors are checking that a firewall exists and is active, not auditing every rule. The compliance policy setting Firewall: Required counts as evidence.

Compliance policy setting: In your Intune compliance policy, set Windows Defender Firewall: Required. Any device without it active will report as non-compliant.

Control 2 - Secure Configuration

This control is about removing unnecessary software and functionality, changing default passwords, and ensuring devices are configured securely out of the box. Intune handles this through configuration profiles and the compliance policy.

Password requirements

Cyber Essentials requires a minimum password length of 8 characters (or 6 if the account locks after 10 attempts). Set this in your compliance policy:

Secure Boot and TPM

Cyber Essentials Plus assessors will check that Secure Boot is enabled. Set this in your compliance policy:

Disable unnecessary features via Configuration Profiles

Create a Settings Catalog profile in Intune to lock down common attack surfaces:

Intune Admin Centre path
Devices Configuration Create Windows 10 and later Settings catalog

Key settings to configure:

Control 3 - User Access Control

This control requires that user accounts have only the access they need, admin accounts are separate from standard user accounts, and MFA is used for all accounts (required since Cyber Essentials v3.1 in April 2023).

MFA for all users via Conditional Access

This is the most important change since the 2023 update to the scheme. Every user account that can access your M365 data must have MFA enforced.

Entra Admin Centre path
Protection Conditional Access Create policy

Create a Conditional Access policy with these settings:

Use the Intune Compliance Builder to download ready-to-import CA policy JSON files for MFA, compliant device, and legacy auth blocking.

Local administrator accounts

Cyber Essentials requires that local admin accounts on devices are not used for day-to-day work. Use Windows LAPS (Local Administrator Password Solution) via Intune to manage local admin accounts with unique, rotating passwords stored in Entra ID.

Intune Admin Centre path
Endpoint security Account protection Create policy Windows LAPS

Privileged accounts

Admin accounts (Global Admin, Intune Admin, etc.) should be cloud-only accounts not used for email or day-to-day browsing. Require MFA on every sign-in for these roles - create a separate Conditional Access policy targeting admin directory roles with no trusted location exclusions.

Control 4 - Malware Protection

Cyber Essentials requires that all devices run up-to-date malware protection with real-time scanning enabled. Microsoft Defender Antivirus, included with Windows 10/11, meets this requirement when properly configured.

Intune Admin Centre path
Endpoint security Antivirus Create policy Windows 10/11 Microsoft Defender Antivirus

Key settings to configure in your Defender Antivirus policy:

Set the following in your compliance policy to enforce the requirement:

Heads up on third-party AV: If you use a third-party antivirus (Sophos, ESET, CrowdStrike etc.), that's fine for Cyber Essentials - just make sure it's actively managed, real-time scanning is on, and definitions are kept up to date. The same compliance policy settings apply.

Control 5 - Patch Management

Cyber Essentials requires that all software on in-scope devices is licensed, supported, and kept up to date. Specifically, high and critical patches must be applied within 14 days of release.

Windows Update for Business via Intune

Create an Update Ring policy in Intune to manage when Windows updates are deployed to devices.

Intune Admin Centre path
Devices Windows updates Update rings for Windows 10 and later Create profile

Recommended settings for Cyber Essentials compliance:

The 14-day rule: Cyber Essentials is specific - critical and high severity patches must be applied within 14 days. Setting your quality update deadline to 7 days gives you a comfortable buffer and keeps assessors happy.

Microsoft 365 Apps updates

Don't forget that the Cyber Essentials patching requirement covers all software, not just Windows. For Microsoft 365 Apps (Word, Excel, Teams etc.), configure the update channel in Intune:

Intune Admin Centre path
Apps Windows Microsoft 365 Apps for Windows 10 and later

Set the update channel to Monthly Enterprise Channel - this receives security updates once per month on the second Tuesday, which keeps you within the 14-day window for critical patches.

Pre-submission checklist

Before you submit your Cyber Essentials self-assessment, run through this list to confirm you have all five controls covered in Intune:

// not sure where your tenant stands?
M365 Security Audit - £349

I audit your Microsoft 365 tenant against the Cyber Essentials controls and produce a written report showing exactly what needs fixing, in priority order. Fixed price, no surprises.

Read-only audit Written report Fixed £349
View Packages →
#cyber-essentials #intune #microsoft-365 #endpoint-security #uk-sme #ncsc #conditional-access
J
Jack Davies
IT Engineer · M365 & Intune Specialist

Jack is an IT Technical Engineer based in the UK, working day-to-day with Microsoft 365, Intune, and Entra ID across a range of businesses. He holds the MS-900 certification and is studying for a BSc in Cyber Security through the Open University. Outside of work he builds and documents home lab projects, writes guides on this site, and takes on M365 consulting work for small businesses.

About Jack → LinkedIn →
// monthly tips

Get M365 tips in your inbox

Practical Intune and Microsoft 365 tips, once a month. No spam, no fluff.