Cyber Essentials for Microsoft Azure: configuration guide
Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.

Section 01
Cyber Essentials for Microsoft Azure: configuration guide
Cyber Essentials v3.3 treats your Azure tenant as in-scope cloud services. Verify effective MFA for human cloud authentication, needed access, supported software and timely required fixes. Conditional Access, PIM and Secure Score are implementation tools, not a mandatory product/score bundle or measured failure ranking.
Section 02
What's in scope
Anything your organisation administers in Azure falls under Cyber Essentials:
- Entra ID (Azure AD) - all user accounts with access to corporate data
- Azure subscriptions - anything you pay for or control
- Virtual machines you operate - OS-level security is your responsibility (IaaS)
- PaaS services you configure - App Service, Functions, SQL Database firewall rules
- Administrative access paths - the Azure portal itself, CLI, PowerShell
Azure's underlying fabric (hypervisor, physical hosts, the control plane) is Microsoft's responsibility under the shared responsibility model and is implemented by the provider; confirm the relevant contractual/shared-responsibility commitments instead of treating provider-delivered controls as absent from the cloud-service scope.
Section 03
1. Identity and authentication (Control: Secure Configuration + User Access Control)
Required controls and implementation choices:
- Effective MFA on human cloud-service authentication. Workload managed identities/service principals need appropriate machine-identity controls, rather than an impossible interactive MFA prompt. Microsoft's "Security Defaults" meet this if you haven't customised. If you have Conditional Access licences (any Entra ID P1+), prefer a Conditional Access policy that requires MFA for all users, all cloud apps.
- Block legacy authentication via Conditional Access. Password-only basic-authentication routes can bypass MFA; IMAP, POP and SMTP can also use OAuth depending on the actual service/client, so verify authentication rather than treating a protocol name alone as proof.
- Apply the full scheme password controls, including an applicable quality route: MFA, twelve or more characters, or eight or more with a common-password deny list. Entra cloud passwords follow Microsoft's supported policy; Conditional Access is not a custom password-length editor.
- No shared admin accounts. Each admin has a named, MFA-enforced account.
Evidence assessors expect: screenshots of the Conditional Access policies, the Security Defaults toggle, and the user list showing MFA status.
Section 04
2. Privileged access
PIM and specific recovery designs below are implementation/hardening options; the required outcome is necessary privileges, separate administrative work and effective authentication.
- Optional just-in-time administration. Minimise privileges to those needed. Use Privileged Identity Management (PIM) to require just-in-time elevation with approval workflows.
- Emergency access: follow Microsoft's current supported design with independent strong authentication and safe recovery. A policy exclusion must not create password-only cloud access; a particular two-account/key-storage design is not a universal scheme requirement.
- Separate admin identities - admin work happens on separate accounts that do not receive email.
Section 05
3. Secure configuration baseline
- Use Microsoft Secure Score as a diagnostic. A seventy-percent target is a local choice; it is not a scheme pass threshold or a one-to-one control mapping.
- Consider Microsoft Defender for Cloud where its current plan/capability fits your needs; it is not a compulsory scheme purchase.
- Disable guest user self-invite and restrict external collaboration to approved domains.
Section 06
4. Firewall and boundary
Cyber Essentials requires a boundary firewall between untrusted networks and devices.
- Network controls: verify effective filtering and approved necessary access using the supported Azure design; an NSG on every subnet is not the scheme's prescribed architecture.
- No 0.0.0.0/0 inbound rules on SSH (22), RDP (3389), or database ports. Use Azure Bastion or a VPN.
- Azure Firewall or a third-party NVA can implement relevant filtering where appropriate; a specific product is not universally mandated.
Section 07
5. Patching customer-operated VMs
For customer-operated VMs, Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance.
- Use supported update tooling such as Azure Update Manager. It is the successor service, not merely a renamed identical product; check supported machines and scheduling.
- Check exact OS edition/version and any qualifying ESU, ESM or extended-support entitlement. Names alone do not determine support. Remove unsupported software or exclude through a defined sub-set preventing all traffic to or from the internet; documentation alone is insufficient.
Section 08
6. Common failure points
1. Legacy auth not blocked. Check the actual tenant configuration and supported client flows rather than assuming a universal default or five-minute fix.
2. One service account with an ancient password and no MFA used by a line-of-business app. Determine whether this is a workload identity or human account; use supported managed/workload identities where suitable. An app password plus Conditional Access exclusion bypasses MFA and must not be described as enforcing it.
3. VMs with public IPs and RDP open. Failure on both firewall and secure-configuration controls.
4. Unnecessary standing privileges. Grant only needed access; there is no scheme maximum of four global admins or universal PIM mandate.
Section 09
What Fig Group checks
The readiness check supports preparation. Share scoped identity, configuration and update evidence when requested. Exact read-only integration and score/pass-rate claims need service and cohort records; diagnostic scores do not guarantee certification.
Start Cyber Essentials for your Azure tenant - from £299.99 + VAT | Full pricing | CE Plus if your assessor is also going to test
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for Microsoft Intune: configuration guide
Use Microsoft Intune configuration, compliance, app protection and update policies to prepare Cyber Essentials evidence across supported platforms.
Read articleTechnical Guides
Cyber Essentials for Jamf Pro: Mac configuration guide
Prepare Jamf Pro Mac configuration and evidence for Cyber Essentials: scope coverage, firewall, supported software, malware protection and optional FileVault hardening.
Read articleTechnical Guides
Cyber Essentials for Mac / macOS: configuration guide
Prepare Mac and macOS controls for Cyber Essentials with or without MDM: firewall, supported software, patching, malware protection and optional FileVault hardening.
Read article

