If half your people work from home and the rest sit in co-work type locations in different cities, you do not have a traditional perimeter. There is no office firewall story that covers a laptop on home Wi-Fi in Brisbane while the finance folder lives in SharePoint in Sydney.
Boards and insurers still ask whether you are doing the Essential Eight. That question does not go away because you went remote. Internacious runs Essential Eight assessments as an operated baseline on Microsoft 365, Entra ID, Intune and Defender, for teams whose "network" is identity and devices rather than a rack in a central office.
Australian organisations of about 5–75 people whose staff work across states, home offices and more than one site. Professional services, NFP and health teams, construction and architecture firms with site plus office patterns, and any Microsoft 365 business that has outgrown "we turned on MFA once."
| Essential Eight control | How we operate it without an office network |
|---|---|
| Application control | Intune allow/deny and hardening where it is practical for your seat count. |
| Patch applications | Intune + Defender update rings; third-party apps in scope, not only Windows Update |
| Microsoft Office macros | Baseline policies that block casual macro risk while allowing the few exceptions your company needs |
| User application hardening | Browser and Office hardening pushed through Intune so home and office devices get the same story |
| Restrict administrative privileges | Least privilege in Entra; separate admin accounts; Conditional Access on privileged roles |
| Patch operating systems | Compliance policies that block access when a device falls behind |
| Multi-factor authentication | MFA as default, with phishing-resistant options where your risk and tooling support them |
| Regular backups | Third-party backup for Exchange, SharePoint, OneDrive and Teams. Microsoft retention does not replace a proper backup product |
Yes. For most of the Eight, Entra, Intune, Defender and proper M365 backup are the control plane. The work is configuring and running them properly across every location, including when there is no LAN.
We can start with a gap view. The point of the page is an operated baseline: controls that stay in place, get reviewed, and produce evidence when the board or insurer asks again.
Generic projects often end in a report. We are a security-first MSP. The same engineers who set Conditional Access and Intune compliance also support your users Australia-wide from Surry Hills.
Company-owned and Intune-managed is the cleanest path. BYOD can work with clear compliance and selective wipe rules. We will say so if your mix is too loose for the maturity you want to claim.
That is normal for us. Policies, patching, wipe and support are remote-native. On-site is available for Sydney when you need it; everyone else is designed to work without a van.
If your board or insurer is asking about Essential Eight and your people are not on one office network, talk to a senior engineer about your real setup.
No lock-in. Bring your current M365 / Intune state and the questions you are getting from the board.
Ready to Talk About Your IT?Book a call