Australian Organizations Must Meet Essential Eight Backups Requirements to Avoid Cyber Threats
The Australian Signals Directorate's Essential Eight is a set of eight mitigation strategies for defending against common cyber threats. One of these controls, 'Regular Backups,' requires that backups of important data be performed and retained in line with business criticality, in a coordinated and resilient manner, with restoration tested.
At Maturity Level 2, the bar rises significantly, requiring that privileged user accounts, other than dedicated backup administrator accounts, be prevented from modifying or deleting backups. This means that even if a ransomware actor compromises a Global Admin account in your Microsoft 365 tenant, they should not be able to touch your backup copies.
A tutorial on tech-insider.org walks through building an Essential Eight Maturity Level 2-aligned backup setup using Microsoft 365 Backup and Azure Backup. The tutorial covers 13 steps, including mapping the data estate, creating a dedicated backup administrator role, enabling Microsoft 365 backup, setting up the Azure backup vault, and configuring backup policies.
The tutorial emphasizes that skipping any of these steps is the single biggest reason these projects stall halfway through. It also notes that an active Azure subscription with an Azure Backup vault or the ability to create one, and Contributor-level access to the target resource group are required for this setup.