Why Most UK Businesses Are Failing Cyber Essentials Control 3 and How 1Password Fixes It

A person types on a laptop with the Cyber Essentials logo and text overlay, connected dots and lines suggesting cyber security, digital networks, and security tools like 1Password.

Cyber Essentials has five controls. Control 3, user access control, is the one most UK businesses arrive at renewal having only partially addressed. The passwords are set. MFA is enabled on email. But shared accounts still exist, privileged access is wider than it needs to be, and somewhere in the business, someone’s credentials are saved in a browser IT does not manage. 1Password for Business closes this gap in a way that iCloud Keychain and browser-based credential storage cannot.

User access control is not the most technically complex of the five Cyber Essentials controls. It does not require specialist tooling to understand. And yet, in our experience, it is the control where businesses most commonly have genuine gaps rather than documentation gaps. The good news is that the gaps are fixable, and under Danzell (v3.3, in force from 27 April 2026), the requirements are clearly stated. This article covers what Control 3 actually requires, where common tools fall short for business use, and how to deploy 1Password across a managed Mac fleet to pass the control cleanly.

What Cyber Essentials Control 3 Actually Requires

Access Control: The Five Things Assessors Check

User access control under Cyber Essentials requires organisations to demonstrate five things:

  1. Unique user accounts. Every person accessing business systems must have their own account. Shared logins for team use are not compliant.
  2. Least-privilege access. Users should only have access to what they need for their role. Admin rights should not be granted by default.
  3. MFA on internet-facing services. Under Danzell, this is now an auto-fail if MFA is available and not enabled, not a correctable non-compliance.
  4. Removal of default passwords. Every device and service must have its default credentials replaced before use.
  5. Disabling or removing unused accounts. Accounts for staff who have left or changed roles must be deactivated promptly.

Under Danzell, the user access control section also explicitly promotes passkeys and FIDO2-based authentication as valid alternatives to traditional password-plus-MFA combinations. For Apple fleets, where passkeys are natively supported across macOS and iOS, this is worth noting. Passkeys satisfy the authentication requirement for account access; MFA remains mandatory on cloud services.

Why This Is the Control Most Businesses Partially Fail

The most common failure modes are consistent across organisations of all sizes. Shared admin credentials exist because they feel convenient. Leavers’ accounts remain active because the offboarding process did not include a step to disable them. (The offboarding article published on 10 June covers this in detail and is worth reading alongside this one.) MFA is enabled on email but not on the three other cloud services the team uses every day. Browser-saved passwords, tied to personal profiles, are providing access to business systems that IT cannot see or audit.

Where iCloud Keychain and Built-In Tools Fall Short for Business

What iCloud Keychain Does Well for Individual Users

iCloud Keychain is an excellent credential management tool for personal use. It is seamless, free, deeply integrated with Safari and the wider Apple ecosystem, and generates strong, unique passwords automatically. For an individual user managing their own personal accounts, it works well and requires no additional setup.

What It Cannot Do for a Managed Business Fleet

For a business attempting to meet Cyber Essentials Control 3, iCloud Keychain has three gaps that are not workarounds but fundamental design limitations.

No central visibility or audit capability. IT cannot see password health across a team via iCloud Keychain. There is no admin console, no reporting interface, and no way for a Cyber Essentials assessor to be shown evidence of password quality across the fleet. Each user’s vault is their own.

Credentials are tied to personal Apple IDs. Unless every staff member is using Managed Apple Accounts for all business functions, credentials saved in iCloud Keychain belong to the individual rather than the organisation. When someone leaves, their credentials leave with them unless the business has an explicit process for credential transfer, which most do not.

No shared vault capability for business credentials. Teams that share access to system accounts, service logins, or third-party platforms have no way to share credentials via iCloud Keychain without sharing the underlying Apple ID. That means staff either know the password (a compliance problem) or share an account (a different compliance problem).

The position here is direct: iCloud Keychain is not sufficient for Cyber Essentials Control 3 compliance in a business environment. This is not a criticism of the tool; it is the wrong tool for the purpose.

What 1Password for Business Adds

Centralised Vault Management and IT Visibility

1Password for Business provides the central visibility and audit capability that iCloud Keychain cannot. Every credential in the organisation exists within a managed vault structure that IT controls. Password health across the entire team is surfaced in the admin console: weak passwords, reused credentials, and accounts not protected by MFA appear as actionable reports rather than invisible risks.

The Admin Console: What IT Can See and Control

The 1Password admin console gives IT the ability to see, manage, and report on credential security across the organisation. Before a Cyber Essentials assessment, the security report shows exactly which accounts have weak passwords, which have reused credentials, and which services are being accessed without MFA. This is the evidence format that assessors want to see. It is also genuinely useful outside of the assessment context: the same report highlights real credential risk the business may not have known about.

Shared Vaults Versus Individual Vaults: How to Structure Access

1Password’s vault structure allows shared credentials to be held centrally without individual staff members knowing the underlying password. A shared vault for a system account or service login grants access to the credential without exposing it. When a staff member’s role changes or they leave the business, vault access is revoked through the admin console and the credential itself remains intact and under IT control. Individual vaults hold personal work credentials, and the separation between shared and individual vaults maps cleanly onto the least-privilege principle that Control 3 requires.

1Password’s Cyber Essentials Alignment: What It Evidences

For Control 3 specifically, 1Password produces three categories of evidence that Cyber Essentials assessors need:

  • Audit logs showing when credentials were accessed, by whom, and from which device
  • Password health reports confirming that default passwords have been replaced, and credential quality meets the required standard
  • MFA enforcement reporting showing which accounts are and are not protected by MFA

1Password integrates with Jamf for deployment and can be pushed to all managed Macs via DMS (formerly MDM) without user action required. The deployment process is straightforward for a fleet already managed through Jamf or Addigy.

Deploying 1Password Across a Managed Mac Fleet

DMS Deployment via Jamf or Apple Business DMS

1Password can be deployed silently to all enrolled Macs via Jamf or through Apple Business Blueprints. The application is available in the Mac App Store for managed distribution, or as a PKG deployment through Jamf Pro. Staff do not need to initiate the installation, agree to prompts, or visit the App Store manually. For a fleet of any size, silent DMS deployment is the right approach: it ensures consistent installation and allows IT to manage updates centrally.

Migrating From Browser-Saved Passwords and Other Tools

The most common friction point when deploying 1Password is credential migration. Staff who have years of passwords saved in Chrome, Safari, or Firefox will not migrate spontaneously. A realistic migration plan for a 50-person team includes: a two-week window for staff to export and import their existing passwords, a clear communication explaining what 1Password replaces and why, and a defined end date after which browser password saving will be disabled via DMS policy. Most businesses find that the migration takes longer than the deployment.

Getting Team Adoption Right: The Change Management Piece

Technical deployment is the easy half. Adoption is the harder half. 1Password succeeds when staff understand what they gain: access to all their credentials from any device, the ability to share access to shared services securely, and the reassurance that if their laptop is lost, their credentials are not. The communication to staff should be specific about what 1Password replaces (browser-saved passwords, spreadsheets of shared credentials, sticky notes), what it does not replace (personal iCloud Keychain for personal use), and what the business requires from the point of deployment. IT leads who treat this as a rollout rather than a tool launch get better adoption rates.

The Practical Guide to Passing Control 3 at Your Next Renewal

The Five-Step Pre-Assessment Checklist

  1. Deploy 1Password to all managed devices via DMS. Ensure every enrolled Mac has the application installed and every staff member has an active account before the assessment date.
  2. Audit all shared accounts and migrate them to shared vaults. Any service previously accessed via a shared login should move to a 1Password shared vault, removing the need for any individual to know the underlying password.
  3. Confirm MFA is enabled on all internet-facing services. Use 1Password’s security report alongside a manual audit of cloud services to confirm MFA is active. Under Danzell, any gap here is an auto-fail.
  4. Remove or disable accounts for leavers. Work through the leaver list for the past 12 months and confirm accounts have been deactivated. Cross-reference against the offboarding checklist.
  5. Run 1Password’s security report and remediate before submitting. The report flags weak, reused, and MFA-unprotected credentials. Remediate before opening the Danzell questionnaire, not after.

We deploy and manage 1Password for Business as part of our IT Success Plans. If your Cyber Essentials renewal is approaching, we can ensure Control 3 is fully covered before you submit.

Related Articles

FAQs

Why is Cyber Essentials Control 3 the most commonly failed control?

Control 3 covers user access management, and the failures are rarely technical. They are process failures: shared accounts that were never cleaned up, leavers whose accounts remain active, MFA enabled on email but not on three other cloud services, and credentials saved in browsers that IT cannot audit. The Danzell update makes several of these failures auto-fail rather than correctable non-compliances, which raises the stakes for businesses that have let access hygiene drift.

Can iCloud Keychain be used to pass Cyber Essentials Control 3?

Not for a business environment. iCloud Keychain has no admin console, no password health reporting, no audit log, and no shared vault capability. Credentials are tied to individual Apple IDs rather than the organisation. Assessors need evidence of password quality and access control across the team; iCloud Keychain cannot produce that evidence. For Cyber Essentials purposes, a centralised, business-managed credential platform such as 1Password for Business is required.

How does 1Password integrate with Jamf for Mac fleet deployment?

1Password can be distributed silently to all Jamf-enrolled Macs via a managed App Store distribution or PKG deployment through Jamf Pro. DMS-managed deployment ensures consistent installation across the fleet without requiring staff to take any action. IT can manage licensing, enforce update policies, and configure MDM-level application settings through the Jamf console alongside the 1Password admin console.

Woman with long dark hair and layered necklaces sits at an outdoor cafe table, with buildings visible in the background.
Paige

Marketing Executive

Paige leads content and marketing at Dr Logic, translating the team's deep technical expertise into practical, straight-talking advice for businesses running on Apple. She covers everything from IT strategy and cyber security to the trends shaping how modern teams work - always with a focus on what actually matters to the people making the decisions.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.