Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

Cyber insurance proposal

Northwind Traders · northwindtraders.onmicrosoft.com

What insurers price the premium on, judged from Microsoft 365 where it can see it. A control missing for the whole organisation is a Fail and a gap on a few accounts is Partly; insurers don't refuse an application for either, they price it or add conditions, so declare both. Match each answer to the question on the form, since wording differs between insurers.

Gaps to close

Northwind Traders has 4 controls not in place.

Judged from Microsoft 365 data collected ; 10 controls need evidence Microsoft 365 can't show.

Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal, which comes round every 12 months.

Gaps to close

9 controls
  1. Legacy authentication is allowed. No enabled policy blocks legacy authentication for all users.

    Fix: Block legacy authentication. See the rows →

  2. 4 of 36 computers not encrypted. For example DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted.

    Fix: Turn on BitLocker. See the rows →

  3. Anyone, including anonymous links. For example SharePoint and OneDrive: Anyone links are allowed.

    Fix: Change SharePoint external sharing to "New and existing guests". See the rows →

  4. Users can consent to any app. Any user can grant any app access to their mail and files.

    Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. See the rows →

  5. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

    Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →

  6. 1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.

    Fix: Remove admin roles from guest accounts. See the rows →

  7. 4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.

    Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →

  8. 1 domain with SPF problems. For example parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing.

    Fix: Publish one SPF record per domain ending in -all. See the rows →

  9. 4 external forwards. For example ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy).

    Fix: Remove forwarding to outside addresses unless the client has a documented business reason. See the rows →

Multi-factor authentication and access

Fail

Every account signs in with MFA, legacy protocols that can't are blocked, administrators are few, separate and named, and accounts go when people do.

Pass
MFA for every user, on email and cloud apps

Multi-factor authentication is enforced for all users accessing email (including webmail and mobile) and cloud applications.

  • Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
  • But: 14 users without MFA.
Users with an MFA method registered
62.2% of 37
Accounts covered by an enforced MFA policy
36 of 36

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins only. Add VPNs, remote desktop and other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
MFA for every administrator

Every privileged and administrator account is protected by MFA.

  • 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
  • But: 1 admin without MFA, and 1 whose registration isn't known.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2

Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").

What Microsoft 365 can't show: Judged for Microsoft 365 and Entra ID admin roles. Add administrators of other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
MFA on remote access

VPN, remote desktop and remote support tools need MFA.

Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Legacy authentication blocked

Sign-in protocols that can't use MFA (IMAP, POP, SMTP AUTH, older Office clients) are blocked.

Gaps
  • Legacy authentication is allowed.
  • No enabled policy blocks legacy authentication for all users
  • SMTP AUTH is on for the organisation.
  • SMTP AUTH is allowed

Fix: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target. See the rows →

Legacy authentication is allowed. No enabled policy blocks legacy sign-in for all users.

What Microsoft 365 can't show: Judged from Conditional Access and Exchange Online settings.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Separate accounts for administration

Administrators use a separate account for admin work, not the one they read email with.

Gaps
  • 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →

Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

What Microsoft 365 can't show: Judged from Microsoft 365 admin role holders: an admin account with a licence or a mailbox looks like an everyday account.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Few, named, internal administrators

Administrator access is limited to a small number of named internal people: no guests, no unnecessary Global Administrators, no apps with admin roles.

  • 2 Global Administrators.
  • Cloud-only tenant: no accounts are synced from on-premises AD.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2
Gaps
  • 1 guest with admin roles.
  • g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
  • 1 app with privileged roles.
  • Some app: App holding Exchange Administrator

Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →

Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.

What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; describe how the list is reviewed.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Leavers and inactive accounts removed

Accounts are disabled promptly when people leave, inactive accounts are removed, and no disabled account keeps a licence.

  • No stale guest invitations.
Gaps
  • 4 accounts inactive for 90+ days or never used.
  • hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
  • sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
  • thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
  • g#EXT#@northwindtraders.example: Guest, never signed in, created ?
  • 1 disabled account still licensed.
  • robert.hughes@northwindtraders.example: Disabled, holding 1 licence

Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →

Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.

What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID (needs Entra ID P1 for last sign-in dates). Describe the leavers process in the answer.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Email security

Partly

Mail is filtered, the domains can't be spoofed, nothing forwards outside unnoticed, and payment changes are verified by voice.

Pass
Incoming mail filtered

Incoming email is filtered for spam, phishing and malicious links and attachments.

  • Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).

Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).

What Microsoft 365 can't show: Microsoft 365 shows which mail gateway the domains route through, not its settings.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
SPF, DKIM and DMARC on every domain

Every email domain publishes SPF, signs with DKIM and has a DMARC policy.

Gaps
  • 1 domain with SPF problems.
  • parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing
  • 1 mail domain without DKIM.
  • northwindtraders.example: Microsoft 365 DKIM isn't set up (selector2 CNAME missing)
  • 2 domains without DMARC enforcement.
  • northwindtraders.example: DMARC is monitor-only (p=none); spoofed mail is still delivered
  • parked.example: Doesn't receive mail but has no DMARC p=reject record

Fix: Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all". See the rows →

SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.

What Microsoft 365 can't show: Judged from public DNS and Exchange Online for the tenant's domains.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
No automatic forwarding outside

Automatic forwarding of email to external addresses is blocked, and inbox rules that forward or hide mail are caught.

  • The default outbound policy blocks automatic external forwarding.
Gaps
  • 4 external forwards.
  • ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy)
  • ann.patel@northwindtraders.example: Inbox rule "Copy to home" forwards to ann.patel.home@homemail.example
  • grace.taylor@northwindtraders.example: Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy)
  • olivia.smith@northwindtraders.example: Inbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.example
  • 1 suspicious inbox rule.
  • ann.patel@northwindtraders.example: ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank

Fix: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset. See the rows →

Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.

What Microsoft 365 can't show: Judged from the Exchange Online outbound spam policy, mailbox forwarding and inbox rules.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Payment changes verified by phone

Requests to change bank details or make payments are verified with a known contact by phone.

Requests to change supplier bank details or make urgent payments are verified by calling the requester on a number already held on file, never one given in the request. Payments over [amount] need approval by [role].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Devices and patching

Fail

Computers are managed, encrypted, protected by EDR, on supported operating systems and patched within 14 days.

Your evidence
EDR on every computer and server

Endpoint detection and response is installed and monitored on all computers and servers.

[EDR product, for example Microsoft Defender for Endpoint] is installed on all [number] computers and servers. Alerts are monitored by [team or security provider] [24/7 or in business hours].

What Microsoft 365 can't show: Office Sentry doesn't read Microsoft Defender; answer from the EDR console.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Managed, encrypted and on supported systems

Company devices are managed, encrypted and run operating systems that still get security updates.

Computers managed by Intune
36
Of which encrypted
32
Windows computers out of support
5
Reaching end of support within 90 days
20
Not compliant
6
Gaps
  • 4 of 36 computers not encrypted.
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SMITH07 (olivia.smith@northwindtraders.example): Windows disk isn't encrypted
  • 6 of 37 managed devices not compliant.
  • DESK-ROBINSON12 (george.robinson@northwindtraders.example): Not compliant
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Not compliant
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Not compliant
  • LAPTOP-SCOTT25 (alfie.scott@northwindtraders.example): Not compliant
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Not compliant
  • and 1 more
  • 5 of 36 Windows computers past end of support.
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • and 20 more

Fix: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. See the rows →

Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.

What Microsoft 365 can't show: Judged for devices known to Intune or Entra ID. Servers, macOS and unmanaged devices aren't seen.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Critical updates within 14 days

Critical security updates are installed within 14 days of release (some forms say 30).

  • But: 3 devices haven't checked in for 30+ days.

Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].

What Microsoft 365 can't show: Intune shows when each device last checked in, not when updates were installed.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Backups and recovery

Your evidence

Data is backed up separately and the restores are tested; there is a plan for an incident and for keeping the business running.

Your evidence
Backups kept separately and tested

Backups are taken regularly, kept offline or immutable and separate from the main systems, and restores are tested.

Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Continuity and recovery plan

A business continuity and disaster recovery plan exists and is tested.

A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Incident response plan

A documented incident response plan says who does what.

A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Monitoring and data

Fail

Activity is logged, suspicious sign-ins are watched, and data only leaves through sharing and apps that are controlled.

Pass
Audit logging on

Audit logging is enabled for email and user activity.

  • Mailbox auditing is on for the organisation.

Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.

What Microsoft 365 can't show: Judged from Exchange Online mailbox auditing and the unified audit log.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Not collected
Suspicious sign-ins monitored

Risky sign-ins and users are detected and acted on.

  • Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2).
  • Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).

Risky users need Entra ID P2.

Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].

What Microsoft 365 can't show: Judged from Entra ID Protection (needs Entra ID P2 for the full detections).

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
External sharing restricted

Sharing files with people outside the organisation is restricted and guests are invited deliberately.

Gaps
  • Anyone, including anonymous links.
  • SharePoint and OneDrive: Anyone links are allowed
  • 3 files and folders shared with anyone.
  • Campaign video.mp4 (Marketing / Documents): Anyone can edit
  • Brand assets (Marketing / Documents): Anyone can view, link never expires
  • holiday.jpg (OneDrive of ann.patel@northwindtraders.example): Anyone can view
  • Anyone, including guests, can invite guests.
  • Guests can invite other guests

Fix: Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only. See the rows →

Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.

What Microsoft 365 can't show: Judged from SharePoint and OneDrive sharing settings and links.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Third-party apps controlled

Users can't consent to third-party apps on their own, and apps with risky permissions are known.

Gaps
  • Users can consent to any app.
  • Any user can grant any app access to their mail and files
  • 1 app with access to mail, files or the directory.
  • Mail Sync Pro: Mail.Read (application permission; unverified publisher)

Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting. See the rows →

Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.

What Microsoft 365 can't show: Judged from Entra ID consent settings and app permissions.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Network and people

Your evidence

A firewall between the network and the internet, no remote desktop open to it, and staff trained to spot phishing.

Your evidence
Firewalls at the internet boundary

Firewalls sit between the network and the internet.

A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
No remote desktop open to the internet

Remote desktop is closed to the internet, or only reachable through a VPN or gateway with MFA.

Remote desktop (RDP) is not reachable from the internet. Remote connections go through [VPN or remote desktop gateway] with multi-factor authentication. This was last confirmed on [date] by [external scan or firewall review].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security awareness training

Staff receive regular security awareness and phishing training.

All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Answers for the form

Cyber insurance proposal

The questions UK cyber insurance proposal and renewal forms usually ask. Wording differs between insurers, so match each answer to the question on the form.

Fill in the 11 answers marked Your input, then copy.

15 answered from Microsoft 365; 11 answered Partly or No. Parts [in brackets] still need filling in.

Multi-factor authentication and access 7 questions

Yes
Is multi-factor authentication (MFA) enforced for all users accessing email, including webmail and mobile?

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

MFA coverage: accounts with a gap → Microsoft 365 data from 11 Oct 2026.

Still to check: This covers Microsoft 365 sign-ins only. Add VPN, remote desktop and any other system people reach from outside the office.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Is MFA required for all remote access to the network, such as VPN, remote desktop and remote support tools?

Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.

Why: Microsoft 365 can't show this. It sees Microsoft 365 sign-ins (see the MFA answer), not VPNs or remote desktop.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Yes
Is MFA enforced for all privileged and administrator accounts?

Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").

Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers Microsoft 365 and Entra ID admin roles. Add admin access to servers, firewalls, backup consoles and other cloud services.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are legacy authentication protocols that can't use MFA blocked?

Legacy authentication is allowed. No enabled policy blocks legacy sign-in for all users.

Legacy sign-ins: what each mailbox allows → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Are administrator accounts separate from the accounts people use every day?

Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers Microsoft 365 admin roles. Add local administrator, server and domain admin accounts.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Is administrator access limited to a small number of named people?

Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.

Admins and roles → Microsoft 365 data from 11 Oct 2026.

Still to check: Add administrators of servers, firewalls and other systems, and say how the list is kept.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are leavers' accounts disabled promptly and inactive accounts removed?

Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.

Inactive accounts → Microsoft 365 data from 11 Oct 2026.

Still to check: Describe the leavers process: who tells IT, and how quickly accounts are disabled.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Email security 4 questions

Yes
Is incoming email filtered for spam, phishing and malicious links and attachments?

Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).

Email domains → Microsoft 365 data from 11 Oct 2026.

Still to check: Office Sentry sees the mail routing and licences, not the filtering policies. Confirm Safe Links and Safe Attachments (or the gateway's equivalent) apply to every user.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are SPF, DKIM and DMARC configured for your email domains?

SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.

Email domains → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Is automatic forwarding of email to external addresses blocked?

Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.

Mail forwarding → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you verify requests to change bank details or make payments by calling a known contact?

Requests to change supplier bank details or make urgent payments are verified by calling the requester on a number already held on file, never one given in the request. Payments over [amount] need approval by [role].

Why: Microsoft 365 can't show this. It's a finance process.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Devices and patching 5 questions

Your input
Is endpoint detection and response (EDR) installed and monitored on all computers and servers?

[EDR product, for example Microsoft Defender for Endpoint] is installed on all [number] computers and servers. Alerts are monitored by [team or security provider] [24/7 or in business hours].

Why: Microsoft 365 can't show this. Office Sentry doesn't read Microsoft Defender for Endpoint or other EDR consoles.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are all operating systems supported and still receiving security updates, with no end-of-life systems?

Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.

Devices: operating systems → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers Windows computers known to Intune or Entra ID. Add servers, macOS, phones, network devices and other software.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Are critical security updates installed within 14 days of release?

Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].

Why: Microsoft 365 can't show this. Intune shows which Windows version each computer runs (see the supported systems answer), not when updates were installed.

Still to check: Some forms ask about 30 days. Answer to the timescale on the form.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are laptops and desktops encrypted?

Company computers managed in Microsoft Intune are not all encrypted. 4 of 36 computers not encrypted.

Devices: managed devices → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers computers managed by Intune. Add any computers that aren't.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are company devices centrally managed?

Company devices are not all managed centrally. 1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant.

Devices: managed devices → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers devices joined to Entra ID. Add any company devices that aren't.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Backups and recovery 3 questions

Your input
Are backups taken regularly, kept offline or immutable, separate from your main systems, and tested?

Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].

Why: Backups aren't visible in Microsoft 365 data. Answer from the backup product's records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you have a business continuity and disaster recovery plan, and is it tested?

A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you have a documented incident response plan?

A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Monitoring and data 4 questions

Yes
Is audit logging enabled for email and user activity?

Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.

Audit logging control → Microsoft 365 data from 11 Oct 2026.

Still to check: How long audit logs are kept depends on the Microsoft 365 licence; confirm the retention period.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you monitor for suspicious sign-ins?

Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].

Why: Sign-in risk needs Entra ID P2.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Is sharing of files with people outside the organisation restricted?

Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.

Guests and sharing: external access settings → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Is access to your data by third-party applications controlled?

Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.

Apps and consents → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Network 2 questions

Your input
Do you have firewalls between your network and the internet?

A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Is remote desktop (RDP) closed to the internet?

Remote desktop (RDP) is not reachable from the internet. Remote connections go through [VPN or remote desktop gateway] with multi-factor authentication. This was last confirmed on [date] by [external scan or firewall review].

Why: Microsoft 365 can't show this. It's a firewall setting.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

People 1 question

Your input
Do staff receive regular security awareness and phishing training?

All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].

Why: Training isn't visible in Microsoft 365 data. Answer from the training provider's records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

About this pack

Scope: insurers ask about the whole business, not one cloud service. A Pass here covers Microsoft 365; the answer should say what covers the rest.

Most forms are signed as a warranty: a wrong answer can void the policy, so a Partly should be declared, not rounded up.

Requirements: UK cyber insurance proposal forms as commonly worded in 2026. Questions drawn from the proposal and renewal forms of UK cyber insurers and brokers, in their typical wording; no insurer's form is copied.

Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .