🎁 Free onboarding credit for Sydney SMBs (new customers).
Internacious • Essential Eight
Remote & Multi-Site Teams

Essential Eight when your team is located across states with no office

If half your people work from home and the rest sit in co-work type locations in different cities, you do not have a traditional perimeter. There is no office firewall story that covers a laptop on home Wi-Fi in Brisbane while the finance folder lives in SharePoint in Sydney.

Boards and insurers still ask whether you are doing the Essential Eight. That question does not go away because you went remote. Internacious runs Essential Eight assessments as an operated baseline on Microsoft 365, Entra ID, Intune and Defender, for teams whose "network" is identity and devices rather than a rack in a central office.

Essential Eight mapped to remote and multi-site work
Operated baseline you keep running
Evidence you can hand over to boards and insurers
Talk to a senior engineer about your real setup
Who it's for

Australian organisations of about 5–75 people whose staff work across states, home offices and more than one site. Professional services, NFP and health teams, construction and architecture firms with site plus office patterns, and any Microsoft 365 business that has outgrown "we turned on MFA once."

You already know identity and devices are the perimeter. You need someone who will operate Essential Eight there. Quoting a firewall for an office network you do not have will not help.

Essential Eight mapped to how remote and multi-site teams work

Essential Eight controlHow we operate it without an office network
Application controlIntune allow/deny and hardening where it is practical for your seat count.
Patch applicationsIntune + Defender update rings; third-party apps in scope, not only Windows Update
Microsoft Office macrosBaseline policies that block casual macro risk while allowing the few exceptions your company needs
User application hardeningBrowser and Office hardening pushed through Intune so home and office devices get the same story
Restrict administrative privilegesLeast privilege in Entra; separate admin accounts; Conditional Access on privileged roles
Patch operating systemsCompliance policies that block access when a device falls behind
Multi-factor authenticationMFA as default, with phishing-resistant options where your risk and tooling support them
Regular backupsThird-party backup for Exchange, SharePoint, OneDrive and Teams. Microsoft retention does not replace a proper backup product

Operated baseline you keep running

  • We assess against the Eight in language a board or insurer can read.
  • We prioritise the gaps that matter for remote and multi-site risk: identity, device compliance, privilege, patching, backup.
  • We implement in your existing Microsoft stack and keep the controls running: reviews, exceptions, drift, and evidence when someone asks again next quarter.
  • Helpdesk and managed IT stay on the same team that owns the security baseline. Dale and senior engineers answer when the conversation is serious.

Evidence you can hand over

  • Clear current state vs target for each control that applies to your environment.
  • Notes on what is enforced in Entra / Intune / Defender / backup, and what is accepted risk.
  • Language aimed at directors, auditors and cyber insurers, written without vendor brochure fluff.

Frequently Asked Questions

Talk to a senior engineer about your real setup

If your board or insurer is asking about Essential Eight and your people are not on one office network, talk to a senior engineer about your real setup.

No lock-in. Bring your current M365 / Intune state and the questions you are getting from the board.

Ready to Talk About Your IT?