Skip to content
Technical Guides

Cyber Essentials for Microsoft Azure: configuration guide

Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.

a close up of a glass building with clouds in

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

7 min read

Share

Section 01

Cyber Essentials for Microsoft Azure: configuration guide

Cyber Essentials v3.3 treats your Azure tenant as in-scope cloud services. Verify effective MFA for human cloud authentication, needed access, supported software and timely required fixes. Conditional Access, PIM and Secure Score are implementation tools, not a mandatory product/score bundle or measured failure ranking.

Section 02

What's in scope

Anything your organisation administers in Azure falls under Cyber Essentials:

  • Entra ID (Azure AD) - all user accounts with access to corporate data
  • Azure subscriptions - anything you pay for or control
  • Virtual machines you operate - OS-level security is your responsibility (IaaS)
  • PaaS services you configure - App Service, Functions, SQL Database firewall rules
  • Administrative access paths - the Azure portal itself, CLI, PowerShell

Azure's underlying fabric (hypervisor, physical hosts, the control plane) is Microsoft's responsibility under the shared responsibility model and is implemented by the provider; confirm the relevant contractual/shared-responsibility commitments instead of treating provider-delivered controls as absent from the cloud-service scope.

Section 03

1. Identity and authentication (Control: Secure Configuration + User Access Control)

Required controls and implementation choices:

  • Effective MFA on human cloud-service authentication. Workload managed identities/service principals need appropriate machine-identity controls, rather than an impossible interactive MFA prompt. Microsoft's "Security Defaults" meet this if you haven't customised. If you have Conditional Access licences (any Entra ID P1+), prefer a Conditional Access policy that requires MFA for all users, all cloud apps.
  • Block legacy authentication via Conditional Access. Password-only basic-authentication routes can bypass MFA; IMAP, POP and SMTP can also use OAuth depending on the actual service/client, so verify authentication rather than treating a protocol name alone as proof.
  • Apply the full scheme password controls, including an applicable quality route: MFA, twelve or more characters, or eight or more with a common-password deny list. Entra cloud passwords follow Microsoft's supported policy; Conditional Access is not a custom password-length editor.
  • No shared admin accounts. Each admin has a named, MFA-enforced account.

Evidence assessors expect: screenshots of the Conditional Access policies, the Security Defaults toggle, and the user list showing MFA status.

Section 04

2. Privileged access

PIM and specific recovery designs below are implementation/hardening options; the required outcome is necessary privileges, separate administrative work and effective authentication.

  • Optional just-in-time administration. Minimise privileges to those needed. Use Privileged Identity Management (PIM) to require just-in-time elevation with approval workflows.
  • Emergency access: follow Microsoft's current supported design with independent strong authentication and safe recovery. A policy exclusion must not create password-only cloud access; a particular two-account/key-storage design is not a universal scheme requirement.
  • Separate admin identities - admin work happens on separate accounts that do not receive email.

Section 05

3. Secure configuration baseline

  • Use Microsoft Secure Score as a diagnostic. A seventy-percent target is a local choice; it is not a scheme pass threshold or a one-to-one control mapping.
  • Consider Microsoft Defender for Cloud where its current plan/capability fits your needs; it is not a compulsory scheme purchase.
  • Disable guest user self-invite and restrict external collaboration to approved domains.

Section 06

4. Firewall and boundary

Cyber Essentials requires a boundary firewall between untrusted networks and devices.

  • Network controls: verify effective filtering and approved necessary access using the supported Azure design; an NSG on every subnet is not the scheme's prescribed architecture.
  • No 0.0.0.0/0 inbound rules on SSH (22), RDP (3389), or database ports. Use Azure Bastion or a VPN.
  • Azure Firewall or a third-party NVA can implement relevant filtering where appropriate; a specific product is not universally mandated.

Section 07

5. Patching customer-operated VMs

For customer-operated VMs, Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance.

  • Use supported update tooling such as Azure Update Manager. It is the successor service, not merely a renamed identical product; check supported machines and scheduling.
  • Check exact OS edition/version and any qualifying ESU, ESM or extended-support entitlement. Names alone do not determine support. Remove unsupported software or exclude through a defined sub-set preventing all traffic to or from the internet; documentation alone is insufficient.

Section 08

6. Common failure points

1. Legacy auth not blocked. Check the actual tenant configuration and supported client flows rather than assuming a universal default or five-minute fix.

2. One service account with an ancient password and no MFA used by a line-of-business app. Determine whether this is a workload identity or human account; use supported managed/workload identities where suitable. An app password plus Conditional Access exclusion bypasses MFA and must not be described as enforcing it.

3. VMs with public IPs and RDP open. Failure on both firewall and secure-configuration controls.

4. Unnecessary standing privileges. Grant only needed access; there is no scheme maximum of four global admins or universal PIM mandate.

Section 09

What Fig Group checks

The readiness check supports preparation. Share scoped identity, configuration and update evidence when requested. Exact read-only integration and score/pass-rate claims need service and cohort records; diagnostic scores do not guarantee certification.

Start Cyber Essentials for your Azure tenant - from £299.99 + VAT | Full pricing | CE Plus if your assessor is also going to test

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group