Skip to content
Security & DefenderChecklist

Cyber Insurance Questionnaire Cheat Sheet for Microsoft 365

The questions cyber insurers ask about MFA, EDR, backups, email security, and admin access, what they really mean, and where each one is answered in Microsoft 365.

Cyber insurance applications have become security audits. Answer "no" to the wrong question and the premium jumps or coverage is declined. Answer "yes" when it isn't true and you risk a denied claim when you need it most. This cheat sheet maps the common questions to where they're actually answered in Microsoft 365, so every "yes" is true and provable.

"Do you require MFA for all remote access and email?"

What they mean: every user, every sign-in to email and cloud apps, and every remote access path (VPN, remote desktop).

Where to check:

  • A Conditional Access policy requires MFA for all users and all cloud apps, or security defaults are on
  • Legacy authentication is blocked, since it can bypass MFA
  • The VPN or remote access tool also requires MFA. It's separate from Microsoft 365 unless you've integrated it.

Evidence: screenshots of the policy, plus the MFA registration report (Entra ID -> Authentication methods -> User registration details).

"Do you require MFA for privileged or admin accounts?"

  • Every account with an admin role requires MFA, preferably phishing-resistant
  • Admins use separate accounts for admin work

Evidence: the list of role holders (Entra ID -> Roles and administrators) and the policy that targets them.

"Do you use endpoint detection and response (EDR)?"

What they mean: not just antivirus, but a tool that records and responds to suspicious behavior.

  • Defender for Business (included in Business Premium) or another EDR is onboarded on every device, not just installed
  • Someone receives and acts on alerts

Evidence: the Defender portal's device inventory, showing all devices with active sensors (onboarding guide).

"Do you have backups, and are they protected from ransomware?"

What they mean: backups that can't be deleted or encrypted by an attacker who gets into your network or tenant, and that you've actually tested.

  • Microsoft 365 data (mail, OneDrive, SharePoint) is backed up by a third-party backup or Microsoft 365 Backup, not just the recycle bin and retention
  • Backups are immutable or offline, with separate credentials
  • A restore has been tested recently
  • Defender for Office 365 Safe Links and Safe Attachments are enabled (Business Premium includes them)
  • SPF, DKIM, and DMARC are in place (setup guide)
  • Automatic external forwarding is blocked

"Are devices encrypted and managed?"

  • Laptops are enrolled in Intune (or another MDM)
  • BitLocker/FileVault is on, with recovery keys escrowed (BitLocker guide)

Evidence: Intune's encryption report.

"Do you patch critical vulnerabilities within X days?"

  • Windows update rings with deadlines are in place (update rings)
  • Browsers and major apps update automatically
  • Firewalls and VPN appliances are patched too. They're a top ransomware entry point (FortiGate checklist).

"Do you provide security awareness training?"

  • Staff complete training at least annually
  • You run phishing simulations. Defender for Office 365 P2 includes Attack simulation training, and third-party options exist.

"Do you have an incident response plan?"

  • A written, one-page plan: who to call (insurer hotline first), how to isolate devices, and where backups live
  • The plan is stored somewhere reachable if Microsoft 365 is compromised
// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.