Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

Supplier security questionnaire

Northwind Traders · northwindtraders.onmicrosoft.com

Due-diligence questionnaires are read by a customer's security team, so the answers should be specific and true. A control missing for the whole organisation is a Fail and a gap on a few accounts is Partly: say what's in place and what's planned. Use the text for the matching question on the client's form.

Gaps to close

Northwind Traders has 4 controls not in place.

Judged from Microsoft 365 data collected ; 13 controls need evidence Microsoft 365 can't show.

Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal.

Gaps to close

13 controls
  1. Anyone, including anonymous links. For example SharePoint and OneDrive: Anyone links are allowed.

    Fix: Change SharePoint external sharing to "New and existing guests". See the rows →

  2. 4 of 36 computers not encrypted. For example DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted.

    Fix: Turn on BitLocker. See the rows →

  3. 5 of 36 Windows computers past end of support. For example LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.

    Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release. See the rows →

  4. Users can consent to any app. Any user can grant any app access to their mail and files.

    Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. See the rows →

  5. 2 admins without a phishing-resistant method. For example ann.patel@northwindtraders.example: Global Administrator; signs in with Authenticator app.

    Fix: Have each listed admin register a passkey. See the rows →

  6. 3 people can only use a text or call as a second factor. For example arthur.evans@northwindtraders.example: Second factor is only Mobile phone (SMS or call).

    Fix: Ask these people to set up the Microsoft Authenticator app. See the rows →

  7. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

    Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →

  8. 1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.

    Fix: Remove admin roles from guest accounts. See the rows →

  9. 4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.

    Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →

  10. Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.

  11. 1 domain with SPF problems. For example parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing.

    Fix: Publish one SPF record per domain ending in -all. See the rows →

  12. 4 external forwards. For example ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy).

    Fix: Remove forwarding to outside addresses unless the client has a documented business reason. See the rows →

  13. 1 of 37 joined computers not in Intune. For example DESK-RECEPTION: Hybrid joined, not managed by Intune.

    Fix: Enrol Entra-joined and hybrid-joined computers in Intune. See the rows →

Governance

Your evidence

Written policies and recognised certifications.

Your evidence
Information security policies

Documented information security policies exist and are reviewed.

Information security policies covering [acceptable use, access control, passwords, data protection and incident response] are approved by [role], reviewed every [12 months] and acknowledged by staff.

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security certifications held

Cyber Essentials, CE Plus, ISO 27001 or similar, with dates.

The organisation holds [Cyber Essentials or Cyber Essentials Plus or ISO 27001] certification, number [certificate number], valid until [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Access control

Partly

Unique accounts with MFA, phishing-resistant for administrators, separate admin accounts, a password policy, and access removed when people leave.

Pass
MFA for every user

Multi-factor authentication is required for all users.

  • Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
  • But: 14 users without MFA.
Users with an MFA method registered
62.2% of 37
Accounts covered by an enforced MFA policy
36 of 36

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins only. Add VPNs, remote desktop and other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
MFA for privileged accounts

Every privileged account uses MFA.

  • 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
  • But: 1 admin without MFA, and 1 whose registration isn't known.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2

Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").

What Microsoft 365 can't show: Judged for Microsoft 365 and Entra ID admin roles.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Phishing-resistant MFA for administrators

Administrators sign in with FIDO2 keys, passkeys or Windows Hello for Business, not codes.

Gaps
  • 2 admins without a phishing-resistant method.
  • ann.patel@northwindtraders.example: Global Administrator; signs in with Authenticator app
  • breakglass@northwindtraders.example: Global Administrator; signs in with no MFA method at all

Fix: Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't. See the rows →

Administrator accounts don't all use phishing-resistant sign-in methods yet. 2 admins without a phishing-resistant method.

What Microsoft 365 can't show: Judged from the sign-in methods admin accounts have registered.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
No weak MFA methods

Text-message and voice-call MFA are turned off or being retired.

Gaps
  • 3 people can only use a text or call as a second factor.
  • arthur.evans@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
  • mia.hughes@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
  • zara.jackson@northwindtraders.example: Second factor is only Mobile phone (SMS or call)

Fix: Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM. See the rows →

Some users rely on a text message or phone call as their only second factor. 3 people can only use a text or call as a second factor.

What Microsoft 365 can't show: Judged from the authentication methods policy and what people have registered.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Separate admin accounts

Administrative accounts are separate from standard user accounts.

Gaps
  • 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →

Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

What Microsoft 365 can't show: Judged from Microsoft 365 admin role holders: an admin account with a licence or a mailbox looks like an everyday account.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Privileged access restricted and tracked

Few named administrators, no guests or apps with admin roles, and the list is reviewed.

  • 2 Global Administrators.
  • Cloud-only tenant: no accounts are synced from on-premises AD.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2
Gaps
  • 1 guest with admin roles.
  • g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
  • 1 app with privileged roles.
  • Some app: App holding Exchange Administrator

Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →

Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.

What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; describe how the list is reviewed.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
Unique accounts, no shared logins

Every user has their own account; shared mailboxes can't be signed in to.

  • All 3 shared mailboxes block sign-in.

Each person signs in to Microsoft 365 with their own named account. Shared mailboxes can't be signed in to directly; people reach them through their own accounts. All 3 shared mailboxes block sign-in.

What Microsoft 365 can't show: Judged from whether shared mailboxes can be signed in to. Check devices and other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
Password policy

Passwords have a minimum length, common ones are banned and repeated failures lock the account.

  • Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.

Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.

What Microsoft 365 can't show: Microsoft Entra ID's defaults (8 characters, a banned password list and smart lockout) aren't read from the tenant. Add other systems that take passwords.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Access removed when people leave

Leavers' accounts are disabled promptly and inactive accounts removed.

Gaps
  • 4 accounts inactive for 90+ days or never used.
  • hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
  • sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
  • thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
  • g#EXT#@northwindtraders.example: Guest, never signed in, created ?
  • 1 disabled account still licensed.
  • robert.hughes@northwindtraders.example: Disabled, holding 1 licence

Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →

Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.

What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID. Describe the leavers process in the answer.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
Guest access reviewed

Guests and external users are reviewed and pending invitations cleared.

  • No stale guest invitations.
  • Guests have limited access to directory objects (the default).

Guest and external user accounts are not reviewed regularly. 1 guest account: 1 guest inactive for 90+ days or never signed in (g#EXT#@northwindtraders.example).

What Microsoft 365 can't show: Judged from guest accounts and the external collaboration settings.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Data protection

Fail

Where data lives, encryption at rest and in transit, and sharing under control.

Pass
Where data is stored

The region the tenant's data is held in.

  • Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.

Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.

What Microsoft 365 can't show: Microsoft 365 reports the tenant's data location; add any other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Encrypted at rest and in transit

Data is encrypted at rest and in transit.

Gaps
  • Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.

Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.

What Microsoft 365 can't show: Microsoft 365 encrypts stored data and connections; add other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
External sharing controlled

Data can't be shared with unauthorised people: sharing settings, anyone links and guest invitations.

Gaps
  • Anyone, including anonymous links.
  • SharePoint and OneDrive: Anyone links are allowed
  • 3 files and folders shared with anyone.
  • Campaign video.mp4 (Marketing / Documents): Anyone can edit
  • Brand assets (Marketing / Documents): Anyone can view, link never expires
  • holiday.jpg (OneDrive of ann.patel@northwindtraders.example): Anyone can view
  • Anyone, including guests, can invite guests.
  • Guests can invite other guests

Fix: Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only. See the rows →

Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.

What Microsoft 365 can't show: Judged from SharePoint and OneDrive sharing settings and links.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Portable devices encrypted

Laptops and other portable devices are encrypted.

Gaps
  • 4 of 36 computers not encrypted.
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SMITH07 (olivia.smith@northwindtraders.example): Windows disk isn't encrypted

Fix: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. See the rows →

Company computers managed in Microsoft Intune are not all encrypted. 4 of 36 computers not encrypted.

What Microsoft 365 can't show: Judged for devices managed by Intune.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Email security

Partly

Mail filtered, domains protected against spoofing, no forwarding outside.

Pass
Mail filtered for phishing and malware

Incoming email is filtered for phishing and malware.

  • Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).

Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).

What Microsoft 365 can't show: Microsoft 365 shows which mail gateway the domains route through, not its settings.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
SPF, DKIM and DMARC

Every email domain publishes SPF, signs with DKIM and has a DMARC policy.

Gaps
  • 1 domain with SPF problems.
  • parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing
  • 1 mail domain without DKIM.
  • northwindtraders.example: Microsoft 365 DKIM isn't set up (selector2 CNAME missing)
  • 2 domains without DMARC enforcement.
  • northwindtraders.example: DMARC is monitor-only (p=none); spoofed mail is still delivered
  • parked.example: Doesn't receive mail but has no DMARC p=reject record

Fix: Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all". See the rows →

SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.

What Microsoft 365 can't show: Judged from public DNS and Exchange Online for the tenant's domains.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
No automatic forwarding outside

Automatic forwarding of email outside the organisation is blocked.

  • The default outbound policy blocks automatic external forwarding.
Gaps
  • 4 external forwards.
  • ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy)
  • ann.patel@northwindtraders.example: Inbox rule "Copy to home" forwards to ann.patel.home@homemail.example
  • grace.taylor@northwindtraders.example: Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy)
  • olivia.smith@northwindtraders.example: Inbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.example
  • 1 suspicious inbox rule.
  • ann.patel@northwindtraders.example: ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank

Fix: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset. See the rows →

Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.

What Microsoft 365 can't show: Judged from the Exchange Online outbound spam policy, mailbox forwarding and inbox rules.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Devices

Fail

Managed to a baseline, supported, patched quickly and protected by anti-malware.

Partly
Devices managed to a baseline

Devices are centrally managed and must meet a security baseline.

Computers managed by Intune
36
Of which encrypted
32
Windows computers out of support
5
Reaching end of support within 90 days
20
Not compliant
6
Gaps
  • 1 of 37 joined computers not in Intune.
  • DESK-RECEPTION: Hybrid joined, not managed by Intune
  • 6 of 37 managed devices not compliant.
  • DESK-ROBINSON12 (george.robinson@northwindtraders.example): Not compliant
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Not compliant
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Not compliant
  • LAPTOP-SCOTT25 (alfie.scott@northwindtraders.example): Not compliant
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Not compliant
  • and 1 more

Fix: Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them. See the rows →

Company devices are not all managed centrally. 1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant.

What Microsoft 365 can't show: Judged from Intune enrolment and compliance for devices joined to Entra ID.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Supported operating systems

Every operating system is still supported by its vendor.

Gaps
  • 5 of 36 Windows computers past end of support.
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • and 20 more

Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. See the rows →

Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.

What Microsoft 365 can't show: Judged for Windows computers known to Intune or Entra ID.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security updates applied quickly

Security updates are applied within an agreed time, 14 days for critical ones.

  • But: 3 devices haven't checked in for 30+ days.

Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].

What Microsoft 365 can't show: Intune shows when each device last checked in, not when updates were installed.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Anti-malware on every device

Anti-malware software is installed and kept up to date on all devices.

  • But: 6 of 37 managed devices not compliant.

All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.

What Microsoft 365 can't show: Office Sentry doesn't read Microsoft Defender or anti-malware settings.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Logging and monitoring

Not collected

Security events logged, suspicious activity watched, vulnerabilities looked for.

Pass
Security events logged

Security events are logged and kept.

  • Mailbox auditing is on for the organisation.

Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.

What Microsoft 365 can't show: Judged from Exchange Online mailbox auditing and the unified audit log.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Not collected
Suspicious activity monitored

Suspicious sign-ins and users are detected and responded to.

  • Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2).
  • Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).

Risky users need Entra ID P2.

Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].

What Microsoft 365 can't show: Judged from Entra ID Protection (needs Entra ID P2 for the full detections).

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Vulnerability scanning or penetration testing

Vulnerability scans or penetration tests are carried out and findings fixed.

External vulnerability scans run [monthly] using [tool or provider]. [A penetration test was last carried out on (date) by (provider).]

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Incidents, backups and continuity

Your evidence

A plan for incidents (and telling the client), tested backups, and continuity plans.

Your evidence
Incident response and notification

An incident response plan exists and clients are told about incidents affecting their data.

A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Backups and tested restores

Data is backed up and restores are tested.

Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Continuity and recovery plans

Business continuity and disaster recovery plans exist.

A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Third parties, people and premises

Fail

Apps and sub-processors under control, staff trained and vetted, premises secured, and a firewall with MFA on remote access.

Fail
Third-party apps controlled

Users can't consent to third-party apps on their own, and apps with risky permissions are known.

Gaps
  • Users can consent to any app.
  • Any user can grant any app access to their mail and files
  • 1 app with access to mail, files or the directory.
  • Mail Sync Pro: Mail.Read (application permission; unverified publisher)

Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting. See the rows →

Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.

What Microsoft 365 can't show: Judged from Entra ID consent settings and app permissions.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
Cloud services and sub-processors

The cloud services and sub-processors that hold the client's data.

  • Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.

Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.

What Microsoft 365 can't show: Microsoft 365 lists the apps connected to its sign-in; add the rest.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security awareness training

Staff receive security awareness training.

All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Staff vetted before access

Staff are vetted before they're given access.

New staff go through [right-to-work, reference and DBS] checks before they get access, and sign [confidentiality agreements].

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Premises and equipment secured

Premises and equipment are physically secured.

Offices are protected by [locked doors, access control and alarms]. [Servers and network equipment are kept in a locked room or cabinet.]

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Network protected by firewalls

The network is protected by firewalls.

A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
MFA on remote access

Remote access is protected by MFA.

Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.

What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Answers for the form

Supplier security questionnaire

What clients ask in supplier and vendor due-diligence questionnaires. Use the text for the matching question on the client's form.

Fill in the 14 answers marked Your input, then copy.

22 answered from Microsoft 365; 14 answered Partly or No. Parts [in brackets] still need filling in.

Governance 2 questions

Your input
Do you have documented information security policies?

Information security policies covering [acceptable use, access control, passwords, data protection and incident response] are approved by [role], reviewed every [12 months] and acknowledged by staff.

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you hold any security certifications, such as Cyber Essentials or ISO 27001?

The organisation holds [Cyber Essentials or Cyber Essentials Plus or ISO 27001] certification, number [certificate number], valid until [date].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Access control 10 questions

Yes
Is multi-factor authentication required for all users?

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

MFA coverage: accounts with a gap → Microsoft 365 data from 11 Oct 2026.

Still to check: This covers Microsoft 365 sign-ins only. Add VPN, remote desktop and any other system people reach from outside the office.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Yes
Is multi-factor authentication required for privileged accounts?

Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").

Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers Microsoft 365 and Entra ID admin roles. Add admin access to servers, firewalls, backup consoles and other cloud services.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Do administrators use phishing-resistant MFA?

Administrator accounts don't all use phishing-resistant sign-in methods yet. 2 admins without a phishing-resistant method.

Passwords and sign-in methods → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Do you avoid weaker MFA methods such as text messages?

Some users rely on a text message or phone call as their only second factor. 3 people can only use a text or call as a second factor.

Passwords and sign-in methods → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Are administrative accounts separate from standard user accounts?

Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.

Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers Microsoft 365 admin roles. Add local administrator, server and domain admin accounts.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Is privileged access restricted and tracked?

Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.

Admins and roles → Microsoft 365 data from 11 Oct 2026.

Still to check: Add administrators of servers, firewalls and other systems, and say how the list is kept.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Yes
Does every user have a unique account, with no shared logins?

Each person signs in to Microsoft 365 with their own named account. Shared mailboxes can't be signed in to directly; people reach them through their own accounts. All 3 shared mailboxes block sign-in.

Shared mailboxes → Microsoft 365 data from 11 Oct 2026.

Still to check: Check devices, line-of-business apps and other systems for shared logins.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Answered
Describe your password policy.

Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.

Passwords and sign-in methods → Microsoft 365 data from 11 Oct 2026.

Still to check: The password rules are Microsoft's defaults, not read from the tenant. Add other systems that use passwords (devices, servers, other cloud services).

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
How quickly is access removed when someone leaves?

Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.

Inactive accounts → Microsoft 365 data from 11 Oct 2026.

Still to check: Describe the leavers process: who tells IT, and how quickly accounts are disabled.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Is access by guests and external users reviewed?

Guest and external user accounts are not reviewed regularly. 1 guest account: 1 guest inactive for 90+ days or never signed in (g#EXT#@northwindtraders.example).

Inactive accounts: inactive guests → Microsoft 365 data from 11 Oct 2026.

Still to check: Say how often guest access is reviewed, and by whom.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Data protection 4 questions

Answered
Where is our data stored?

Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.

Microsoft 365 data from 11 Oct 2026.

Still to check: Confirm the data location in the Microsoft 365 admin centre (Settings > Org settings > Organization profile > Data location), and add data held anywhere else.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Is data encrypted at rest and in transit?

Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.

Devices: managed devices → Microsoft 365 data from 11 Oct 2026.

Still to check: The Microsoft 365 encryption is Microsoft's own, not read from the tenant. Add servers, backups and other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
How do you stop data being shared with unauthorised people?

Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.

Guests and sharing: external access settings → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are laptops and other portable devices encrypted?

Company computers managed in Microsoft Intune are not all encrypted. 4 of 36 computers not encrypted.

Devices: managed devices → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers computers managed by Intune. Add any computers that aren't.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Email security 3 questions

Yes
How is email protected against phishing and malware?

Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).

Email domains → Microsoft 365 data from 11 Oct 2026.

Still to check: Office Sentry sees the mail routing and licences, not the filtering policies. Confirm Safe Links and Safe Attachments (or the gateway's equivalent) apply to every user.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Do you use SPF, DKIM and DMARC to stop your domains being spoofed?

SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.

Email domains → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Is automatic forwarding of email outside the organisation blocked?

Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.

Mail forwarding → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Devices 4 questions

No
Are devices centrally managed and required to meet a security baseline?

Company devices are not all managed centrally. 1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant.

Devices: managed devices → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers devices joined to Entra ID. Add any company devices that aren't.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

No
Are all operating systems supported by their vendor?

Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.

Devices: operating systems → Microsoft 365 data from 11 Oct 2026.

Still to check: Covers Windows computers known to Intune or Entra ID. Add servers, macOS, phones, network devices and other software.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
How quickly are security updates applied?

Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].

Why: Microsoft 365 can't show this. Intune shows which Windows version each computer runs (see the supported systems answer), not when updates were installed.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Is anti-malware software installed and kept up to date on all devices?

All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.

Why: Microsoft 365 can't show this. Office Sentry doesn't read anti-malware settings.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Logging and monitoring 3 questions

Yes
Are security events logged?

Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.

Audit logging control → Microsoft 365 data from 11 Oct 2026.

Still to check: How long audit logs are kept depends on the Microsoft 365 licence; confirm the retention period.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you monitor for and respond to suspicious activity?

Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].

Why: Sign-in risk needs Entra ID P2.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you carry out vulnerability scanning or penetration testing?

External vulnerability scans run [monthly] using [tool or provider]. [A penetration test was last carried out on (date) by (provider).]

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Incidents, backups and continuity 3 questions

Your input
Do you have an incident response plan, and would you tell us about an incident affecting our data?

A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Is data backed up, and are restores tested?

Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].

Why: Backups aren't visible in Microsoft 365 data. Answer from the backup product's records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Do you have business continuity and disaster recovery plans?

A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Third parties 2 questions

No
How do you control third-party applications' access to data?

Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.

Apps and consents → Microsoft 365 data from 11 Oct 2026.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Answered
Which cloud services and sub-processors do you use?

Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.

Apps and consents → Microsoft 365 data from 11 Oct 2026.

Still to check: Add cloud services people sign in to with separate accounts (accounting, payroll, CRM, file transfer, social media); Microsoft 365 can't see them.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

People and premises 3 questions

Your input
Do staff receive security awareness training?

All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].

Why: Training isn't visible in Microsoft 365 data. Answer from the training provider's records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Are staff vetted before they're given access?

New staff go through [right-to-work, reference and DBS] checks before they get access, and sign [confidentiality agreements].

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
How are your premises and equipment secured?

Offices are protected by [locked doors, access control and alarms]. [Servers and network equipment are kept in a locked room or cabinet.]

Why: Microsoft 365 can't show this.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Network 2 questions

Your input
Is your network protected by firewalls?

A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.

Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your input
Is remote access protected by multi-factor authentication?

Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.

Why: Microsoft 365 can't show this. It sees Microsoft 365 sign-ins (see the MFA answer), not VPNs or remote desktop.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

About this pack

Scope: the client's customer asks about the client's whole business. A Pass here covers Microsoft 365; the answer should say what covers the rest.

Requirements: Supplier and vendor due-diligence questionnaires as commonly worded in 2026. Questions drawn from the supplier security questionnaires UK organisations send their suppliers, in their typical wording; no organisation's form is copied.

Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .