Cyber Essentials has five controls. Control 3, user access control, is the one most UK businesses arrive at renewal having only partially addressed. The passwords are set. MFA is enabled on email. But shared accounts still exist, privileged access is wider than it needs to be, and somewhere in the business, someone’s credentials are saved in a browser IT does not manage. 1Password for Business closes this gap in a way that iCloud Keychain and browser-based credential storage cannot.
User access control is not the most technically complex of the five Cyber Essentials controls. It does not require specialist tooling to understand. And yet, in our experience, it is the control where businesses most commonly have genuine gaps rather than documentation gaps. The good news is that the gaps are fixable, and under Danzell (v3.3, in force from 27 April 2026), the requirements are clearly stated. This article covers what Control 3 actually requires, where common tools fall short for business use, and how to deploy 1Password across a managed Mac fleet to pass the control cleanly.
What Cyber Essentials Control 3 Actually Requires
Access Control: The Five Things Assessors Check
User access control under Cyber Essentials requires organisations to demonstrate five things:
- Unique user accounts. Every person accessing business systems must have their own account. Shared logins for team use are not compliant.
- Least-privilege access. Users should only have access to what they need for their role. Admin rights should not be granted by default.
- MFA on internet-facing services. Under Danzell, this is now an auto-fail if MFA is available and not enabled, not a correctable non-compliance.
- Removal of default passwords. Every device and service must have its default credentials replaced before use.
- Disabling or removing unused accounts. Accounts for staff who have left or changed roles must be deactivated promptly.
Under Danzell, the user access control section also explicitly promotes passkeys and FIDO2-based authentication as valid alternatives to traditional password-plus-MFA combinations. For Apple fleets, where passkeys are natively supported across macOS and iOS, this is worth noting. Passkeys satisfy the authentication requirement for account access; MFA remains mandatory on cloud services.
Why This Is the Control Most Businesses Partially Fail
The most common failure modes are consistent across organisations of all sizes. Shared admin credentials exist because they feel convenient. Leavers’ accounts remain active because the offboarding process did not include a step to disable them. (The offboarding article published on 10 June covers this in detail and is worth reading alongside this one.) MFA is enabled on email but not on the three other cloud services the team uses every day. Browser-saved passwords, tied to personal profiles, are providing access to business systems that IT cannot see or audit.
Where iCloud Keychain and Built-In Tools Fall Short for Business
What iCloud Keychain Does Well for Individual Users
iCloud Keychain is an excellent credential management tool for personal use. It is seamless, free, deeply integrated with Safari and the wider Apple ecosystem, and generates strong, unique passwords automatically. For an individual user managing their own personal accounts, it works well and requires no additional setup.
What It Cannot Do for a Managed Business Fleet
For a business attempting to meet Cyber Essentials Control 3, iCloud Keychain has three gaps that are not workarounds but fundamental design limitations.
No central visibility or audit capability. IT cannot see password health across a team via iCloud Keychain. There is no admin console, no reporting interface, and no way for a Cyber Essentials assessor to be shown evidence of password quality across the fleet. Each user’s vault is their own.
Credentials are tied to personal Apple IDs. Unless every staff member is using Managed Apple Accounts for all business functions, credentials saved in iCloud Keychain belong to the individual rather than the organisation. When someone leaves, their credentials leave with them unless the business has an explicit process for credential transfer, which most do not.
No shared vault capability for business credentials. Teams that share access to system accounts, service logins, or third-party platforms have no way to share credentials via iCloud Keychain without sharing the underlying Apple ID. That means staff either know the password (a compliance problem) or share an account (a different compliance problem).
The position here is direct: iCloud Keychain is not sufficient for Cyber Essentials Control 3 compliance in a business environment. This is not a criticism of the tool; it is the wrong tool for the purpose.
What 1Password for Business Adds
Centralised Vault Management and IT Visibility
1Password for Business provides the central visibility and audit capability that iCloud Keychain cannot. Every credential in the organisation exists within a managed vault structure that IT controls. Password health across the entire team is surfaced in the admin console: weak passwords, reused credentials, and accounts not protected by MFA appear as actionable reports rather than invisible risks.
The Admin Console: What IT Can See and Control
The 1Password admin console gives IT the ability to see, manage, and report on credential security across the organisation. Before a Cyber Essentials assessment, the security report shows exactly which accounts have weak passwords, which have reused credentials, and which services are being accessed without MFA. This is the evidence format that assessors want to see. It is also genuinely useful outside of the assessment context: the same report highlights real credential risk the business may not have known about.
Shared Vaults Versus Individual Vaults: How to Structure Access
1Password’s vault structure allows shared credentials to be held centrally without individual staff members knowing the underlying password. A shared vault for a system account or service login grants access to the credential without exposing it. When a staff member’s role changes or they leave the business, vault access is revoked through the admin console and the credential itself remains intact and under IT control. Individual vaults hold personal work credentials, and the separation between shared and individual vaults maps cleanly onto the least-privilege principle that Control 3 requires.
1Password’s Cyber Essentials Alignment: What It Evidences
For Control 3 specifically, 1Password produces three categories of evidence that Cyber Essentials assessors need:
- Audit logs showing when credentials were accessed, by whom, and from which device
- Password health reports confirming that default passwords have been replaced, and credential quality meets the required standard
- MFA enforcement reporting showing which accounts are and are not protected by MFA
1Password integrates with Jamf for deployment and can be pushed to all managed Macs via DMS (formerly MDM) without user action required. The deployment process is straightforward for a fleet already managed through Jamf or Addigy.
Deploying 1Password Across a Managed Mac Fleet
DMS Deployment via Jamf or Apple Business DMS
1Password can be deployed silently to all enrolled Macs via Jamf or through Apple Business Blueprints. The application is available in the Mac App Store for managed distribution, or as a PKG deployment through Jamf Pro. Staff do not need to initiate the installation, agree to prompts, or visit the App Store manually. For a fleet of any size, silent DMS deployment is the right approach: it ensures consistent installation and allows IT to manage updates centrally.
Migrating From Browser-Saved Passwords and Other Tools
The most common friction point when deploying 1Password is credential migration. Staff who have years of passwords saved in Chrome, Safari, or Firefox will not migrate spontaneously. A realistic migration plan for a 50-person team includes: a two-week window for staff to export and import their existing passwords, a clear communication explaining what 1Password replaces and why, and a defined end date after which browser password saving will be disabled via DMS policy. Most businesses find that the migration takes longer than the deployment.
Getting Team Adoption Right: The Change Management Piece
Technical deployment is the easy half. Adoption is the harder half. 1Password succeeds when staff understand what they gain: access to all their credentials from any device, the ability to share access to shared services securely, and the reassurance that if their laptop is lost, their credentials are not. The communication to staff should be specific about what 1Password replaces (browser-saved passwords, spreadsheets of shared credentials, sticky notes), what it does not replace (personal iCloud Keychain for personal use), and what the business requires from the point of deployment. IT leads who treat this as a rollout rather than a tool launch get better adoption rates.
The Practical Guide to Passing Control 3 at Your Next Renewal
The Five-Step Pre-Assessment Checklist
- Deploy 1Password to all managed devices via DMS. Ensure every enrolled Mac has the application installed and every staff member has an active account before the assessment date.
- Audit all shared accounts and migrate them to shared vaults. Any service previously accessed via a shared login should move to a 1Password shared vault, removing the need for any individual to know the underlying password.
- Confirm MFA is enabled on all internet-facing services. Use 1Password’s security report alongside a manual audit of cloud services to confirm MFA is active. Under Danzell, any gap here is an auto-fail.
- Remove or disable accounts for leavers. Work through the leaver list for the past 12 months and confirm accounts have been deactivated. Cross-reference against the offboarding checklist.
- Run 1Password’s security report and remediate before submitting. The report flags weak, reused, and MFA-unprotected credentials. Remediate before opening the Danzell questionnaire, not after.
We deploy and manage 1Password for Business as part of our IT Success Plans. If your Cyber Essentials renewal is approaching, we can ensure Control 3 is fully covered before you submit.
Related Articles
- What Happens to a Mac When an Employee Leaves: The Offboarding Steps Most Businesses Skip
- What Cyber Essentials Certification Actually Looks Like for an All-Mac Office
FAQs
Why is Cyber Essentials Control 3 the most commonly failed control?
Control 3 covers user access management, and the failures are rarely technical. They are process failures: shared accounts that were never cleaned up, leavers whose accounts remain active, MFA enabled on email but not on three other cloud services, and credentials saved in browsers that IT cannot audit. The Danzell update makes several of these failures auto-fail rather than correctable non-compliances, which raises the stakes for businesses that have let access hygiene drift.
Can iCloud Keychain be used to pass Cyber Essentials Control 3?
Not for a business environment. iCloud Keychain has no admin console, no password health reporting, no audit log, and no shared vault capability. Credentials are tied to individual Apple IDs rather than the organisation. Assessors need evidence of password quality and access control across the team; iCloud Keychain cannot produce that evidence. For Cyber Essentials purposes, a centralised, business-managed credential platform such as 1Password for Business is required.
How does 1Password integrate with Jamf for Mac fleet deployment?
1Password can be distributed silently to all Jamf-enrolled Macs via a managed App Store distribution or PKG deployment through Jamf Pro. DMS-managed deployment ensures consistent installation across the fleet without requiring staff to take any action. IT can manage licensing, enforce update policies, and configure MDM-level application settings through the Jamf console alongside the 1Password admin console.



















































