First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI Microsoft partner since 2006 1,100+ organizations under management

The Cyber Insurance Questionnaire: Where the Microsoft 365 Evidence for Each Question Lives

2026-09-20·IT PartnerNewSecurityComplianceMicrosoft 365

A cyber insurance questionnaire arrives with a deadline, a page of yes/no questions and a signature line. Every yes is an attestation, and if a claim is contested the carrier asks what was in place on the day. In a Microsoft 365 tenant most of that evidence already exists as a report or an export; the work is knowing which portal holds it and who can pull it.

Answer from an export, not from memory

Every answer is backed by a dated export or screenshot, filed where a claim can find it. Exceptions are enumerated, not averaged away: "MFA enforced for 212 of 214 users; two documented service accounts excluded and monitored" beats an unqualified yes. And a no with a dated remediation plan is the honest answer when the control is missing; what a no means for coverage is your broker's question.

Two items appear on more questionnaires than a few years ago: a named incident response provider with an engagement in place, and the post-incident report from the last incident, if there was one. Both are documents, easier to produce before the renewal than during a claim.

Most exports below need only a read-only role: Global Reader for the admin centers, Security Reader for the Defender portal, and the reader roles in Intune and Purview.

Identity: MFA and privileged access

The MFA questions (email, remote access, administrators) are all answered by Conditional Access, not by the legacy per-user MFA setting. Conditional Access policies every business should have sets out the baseline: MFA for all users on all cloud apps, legacy authentication blocked, phishing-resistant strength for administrator roles, only emergency access accounts excluded.

The evidence is the policy set. The Conditional Access page in the Entra admin center lists every policy with its state (on, off or report-only); record each policy's assignments and controls. Pair it with the User registration details report under Authentication methods, which shows per user whether MFA is registered and which methods, and exports to CSV; rows with nothing registered are your exception list. A sign-in log filtered to legacy authentication clients should be empty. Remote access through Entra is covered by the same export; a third-party VPN needs that vendor's MFA configuration.

Privileged access management means Privileged Identity Management, which needs Microsoft Entra ID P2 for the administrators in scope (P1 vs P2 explains the counting). The evidence is the PIM role settings, the PIM audit history and a count of permanent Global Administrators, ideally only the two break-glass accounts; Microsoft Entra PIM and Privileged Access Hardening produces that inventory and the role model. Without P2, the honest answer is a documented administrator list with MFA enforced and a review date.

Endpoints: EDR, patching and encryption

"EDR on every endpoint" is answered by Microsoft Defender for Business, which Microsoft 365 Business Premium carries and which is also sold standalone, or by Defender for Endpoint on enterprise plans. The evidence is the device inventory in the Defender portal, exported: onboarding status, sensor health and last-seen date. Reconcile the export against the Intune and Entra device lists, and treat any device missing from Defender as unmanaged. The Tenant Optimizer scan reads devices, Intune compliance and groups from the same sources into an Excel workbook.

Patching cadence is the Intune Windows update reports by device and ring, Windows Autopatch reports where it is in use (Windows Autopatch Implementation covers Business Premium as well as E3 and E5 tenants), and the Defender Vulnerability Management list of outstanding weaknesses. Autopatch is a client service; servers need their own evidence.

Encryption at rest on devices is the Intune encryption report (BitLocker status per device) plus a compliance policy that requires it. Encryption inside the service is Microsoft's service-side encryption and TLS, attested per Microsoft's documentation rather than exported. Outbound sensitive email is Purview Message Encryption and its mail flow rules.

Email, backups and logging

Email filtering and link protection: the Defender portal's threat policies page lists anti-phishing, anti-spam, anti-malware, Safe Links and Safe Attachments policies; export each with its scope. Business Premium carries Defender for Office 365 Plan 1 per Microsoft's documentation at the time of writing. Add SPF, DKIM and DMARC (setup order).

Backups that are offline or immutable, and tested: the native Microsoft 365 Backup covers Exchange Online, SharePoint and OneDrive, is Microsoft-resident and is limited to one year of protection (native vs third-party); Microsoft bills it on protected volume, and that meter is yours. For servers and Azure workloads, Azure Backup Immutable Vault and Ransomware Hardening locks vault immutability, sets soft-delete retention and adds multi-user authorization through a Resource Guard owned by a second administrator; the evidence is the vault properties page and the Resource Guard. "Tested" means a restore drill with evidence: the Microsoft 365 Restore Drill and Recovery Runbook produces per-scenario timestamps, elapsed time, item counts and the restore session record.

Logging and retention: confirm Purview audit is enabled and record the audit retention policies. Audit (Standard) and Audit (Premium) differ in retention and in events such as MailItemsAccessed, and Entra sign-in log retention depends on licensing, so longer windows need Sentinel or storage export. If your tenant were breached today, what could you prove sets a working baseline of at least 90 days of searchable evidence. The evidence is the retention policy page, a search returning the oldest record you claim, and the Sentinel retention setting.

People, plans and vendors

Security awareness training and phishing simulation: the artifact is a dated campaign report with click and compromise rates and training completion. That is Attack Simulation Training in Defender for Office 365, which needs Plan 2 or Microsoft 365 E5 for enrolled users. Managed Security Awareness Training and Phishing Simulation ($375 per tenant per month plus $3 per enrolled user per month) runs it monthly and delivers quarterly reports formatted for insurers.

Incident response plan and a named provider: a written plan with roles and contacts, and an engagement with a provider who will answer. Security Managed Service: Incident Response is a fixed-price investigation ($700 per project) that ends in a report with recommendations; Defender XDR Incident Readiness and Automated Response sets remediation levels and automatic attack disruption with a written exclusion register. Keep any past incident report; the redacted sample report (PDF) shows the shape carriers expect.

Vendor and subprocessor management: for Microsoft's side, point to Microsoft's published audit reports and Product Terms. For yours, keep a register of every vendor with access to company data, the enterprise applications inventory from Entra with permissions and consent grants, and the partner relationships holding admin access to the tenant.

Frequently asked questions

Is Microsoft Authenticator push enough for the MFA question?

Usually yes, because the question is whether MFA is enforced for everyone. Adversary-in-the-middle phishing defeats push approval, so move administrators to phishing-resistant methods first.

We are on Business Premium. Which questions does it already answer?

Entra ID P1 for Conditional Access, Intune for compliance and encryption reporting, and Defender for Business for EDR. It does not carry PIM (Entra ID P2), Audit (Premium) retention or Attack Simulation Training (Defender for Office 365 Plan 2).

Does Microsoft 365 Backup count as an offline or immutable backup?

It is a Microsoft-resident recovery service with a one-year limit, not a copy in separate storage; a copy outside the production platform is a third-party product or, for servers, an Azure Backup vault with immutability locked.

Who should collect the evidence, and with what access?

One owner, read-only roles, one dated folder in SharePoint. The Compliance Evidence and Audit Readiness Retainer ($950 per month per tenant) refreshes the same artifacts monthly and drafts questionnaire answers.

What if we cannot honestly answer yes?

Answer no, attach the remediation plan with dates, and close the gap before the next renewal. We do not advise on coverage, limits or premiums.

Sources

  • IT Partner service pages under content/services: ITPWW350SECOT, ITPWW1110IMPOT, ITPWW500CONOT, PRP-BKP-001, ITPWW320MSPRC, ITPWW520SECOT, ITPWW220MSPOT, ITPWW490SECOT, ITPWW850IMPOT, ITPWW430MSPRC, ITPWW305IMPOT, ITPWW400IMPOT
  • IT Partner subscription pages under content/subscriptions: CFQ7TTC0LCHC, CFQ7TTC0HX56, CFQ7TTC0LFLS
  • IT Partner blog posts linked above; src/app/tools/tenant-optimizer/page.tsx; the sample post-incident report under public/samples/ITPWW540SECOT
  • IT Partner engineering notes, September 2026 (which questions recur; the growing requests for a named provider and a post-incident report)
  • Statements marked "per Microsoft's documentation at the time of writing" were not verified against Microsoft Learn from this environment; confirm them in the admin center.
Question Microsoft 365 control Evidence to export Who can pull it
MFA on email, remote access, administrators Conditional Access: MFA for all users, legacy authentication blocked, authentication strength for roles Policy export; registration details CSV; legacy sign-in filter Global Reader
Privileged access management PIM eligible roles; two break-glass accounts PIM role settings and audit history; permanent Global Administrator count Global Reader (P2)
EDR on every endpoint Defender for Business or Endpoint Device inventory export reconciled with Intune and Entra Security Reader
Patching cadence Intune update rings; Autopatch; Vulnerability Management Update and Autopatch reports; weakness list Intune Read Only Operator
Encryption BitLocker via Intune; service-side encryption and TLS; Purview Message Encryption Encryption report; compliance policy; mail flow rules Intune Read Only Operator
Email filtering and link protection Defender for Office 365 policies; SPF, DKIM, DMARC Threat policies with scope; DNS records Security Reader
Backups immutable and tested Azure Backup immutability locked, soft delete, Resource Guard; Microsoft 365 Backup; restore drill Vault properties; drill evidence pack Azure Reader; recovery owner
Logging and retention Purview audit (Standard or Premium); Sentinel export Retention policies; oldest-record search; workspace retention Global Reader
Training and phishing simulation Attack Simulation Training or third-party platform Campaign reports; training completion Security Reader
Incident response plan, named provider Written plan; provider engagement; Defender XDR readiness Plan; engagement letter; last post-incident report Owner or IT manager
Vendor and subprocessor management Vendor register; Microsoft audit reports and Product Terms; app consents; partner relationships Register; enterprise applications export; partner list IT manager

Key takeaways

  • Treat every yes as an attestation: back it with a dated export, enumerate the exceptions, and file the pack where a claim can find it.
  • Identity questions are answered by the Conditional Access policy set and the registration report; privileged access by PIM settings and a permanent-administrator count.
  • Endpoint questions are answered by the Defender device inventory reconciled against Intune and Entra, plus the Intune encryption and update reports.
  • Backup questions need immutability settings you can show and a restore drill with timestamps; logging questions need the audit retention policy and the oldest record you can search.
  • Training reports, a written response plan with a named provider and a vendor register are documents, not settings; produce them before the renewal.

The Cyber Insurance Readiness Assessment is a one-week, $1,950 fixed-price engagement that maps your Microsoft 365 and Azure controls to the carrier question areas and hands you an evidence pack, a truthful-attestation checklist and a gap-fix plan; it does not advise on coverage or premiums. For IT Partner clients, the Microsoft 365 Security Assessment is available at no charge, and Enable MFA for All Users ($700 per project) closes the most common gap.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.