ACSC Essential Eight
Map your identity controls to the Essential Eight.
ID Posture aligns Entra ID findings to the ACSC Essential Eight mitigation strategies, so you can evidence progress to your board, auditor, or cyber insurer.
The two strategies ID Posture maps to
Mitigation strategy
Level
How ID Posture helps
Status
E8-5 -- Restrict administrative privileges
Level: ML1-ML3
Maps standing vs. eligible privileged roles, PIM usage, subscription-level Owner/Contributor sprawl, and over-privileged managed identities.
Mapped
E8-7 -- Multi-factor authentication
Level: ML1-ML3
Maps MFA registration coverage, Conditional Access policy gaps, and legacy authentication protocol usage.
Mapped
What this page does not assess
ID Posture evaluates identity security posture in Microsoft Entra ID and Azure RBAC. This gives visibility into two Essential Eight mitigation strategies only, it is not full Essential Eight coverage.
- E8-1 -- Application control
- E8-2 -- Patch applications
- E8-3 -- Configure Microsoft Office macro settings
- E8-4 -- User application hardening
- E8-6 -- Patch operating systems
- E8-8 -- Regular backups
These six controls are endpoint, patching, and backup concerns outside what Entra ID data can show. Assess them through your endpoint management and backup tooling.
ID Posture also maps identity findings to 5 controls in ISO/IEC 27001:2022 Annex A, a separate, independently-enabled mapping.
See where you stand against E8-5 and E8-7.
A live walkthrough on your own tenant, no slideware.